Security Policy
Last updated: July 26, 2026
Overview
Ousley.ai is a brand of Nimblor LLC. This page explains how to report a security or privacy issue in anything we operate, and what you can expect back. The machine-readable version of this policy is published at /.well-known/security.txt (RFC 9116).
Current status
Ousley is a pre-release, invitation-only alpha. There is no public build and no live product service at this time — nothing is distributed for download and there is no hosted product API open to the public. The surface that exists to test today is:
- the marketing website, www.ousley.ai; and
- the tester portal at www.ousley.ai/portal (passwordless magic-link sign-in — most of its release configuration is deliberately unset, so it fails closed on consent, entitlement, and download).
Reporting a vulnerability
Email contact@nimblor.com with what you found and where (URL, endpoint, or file), how to reproduce it (steps, and a minimal proof-of-concept if you have one), and the impact you believe it has.
Please report privately by email first — do not disclose the finding publicly before we have had a chance to look at it and respond. We do not currently publish an encryption key; if you need an encrypted channel for something sensitive, say so in a first message and we will arrange one.
What to expect
We are a small, pre-release team and do not yet run a dedicated security on-call rotation, so we do not promise a fixed acknowledgement or resolution time — we would rather set no deadline than one we cannot reliably keep. What we do commit to: reports sent to the address above are read; we will reply as promptly as we reasonably can; and once we have triaged an issue we will tell you how we intend to handle it and keep you informed over email. If you have not heard back in a reasonable time, a polite follow-up is welcome.
Safe harbor for good-faith research
We will not pursue or support legal action against you for security research conducted in good faith under this policy. To stay in good faith:
- act only against the in-scope surfaces below, using your own accounts and data;
- do not access, modify, or exfiltrate data that is not yours, and stop at the minimum proof needed to demonstrate the issue;
- do not degrade, disrupt, or overload the service — no denial-of-service, no high-volume automated scanning that affects availability, no spam;
- do not use social engineering, phishing, or physical attacks against us, our staff, or our vendors;
- give us a reasonable opportunity to address the issue before disclosing it.
If you are unsure whether something is allowed, ask first at the address above.
Scope
In scope (what exists to test today):
- the website
www.ousley.aiand its content; - the tester portal at
www.ousley.ai/portaland its API under/api/portal/.
Out of scope / not currently testable:
- the Ousley product client and any downloadable build — there is no public artifact to test;
- the hosted gateway / model-serving backend — it is not publicly deployed;
- findings that require a released product or an open beta, neither of which exists yet;
- automated-scanner output with no demonstrated, reproducible impact;
- issues in third-party services we use (report those to the vendor); the providers the site relies on are listed in the privacy notice.
No bug-bounty program
We do not offer monetary rewards or run a paid bug-bounty program. We are genuinely grateful for good-faith reports and, with your permission, are happy to credit you once an issue is resolved.
Contact
For security or privacy reports, contact Nimblor LLC at contact@nimblor.com.