Responsible Disclosure

Last updated: 23 August 2026

NT360 Sdn Bhd operates GhostAnalyst. We welcome reports of security vulnerabilities from anyone, and we will not pursue legal action against researchers who follow this policy in good faith.

1. How to report

Use the contact form and select "Report a security vulnerability" as the subject, or email support@ghostanalyst.ai with "Security" in the subject line. Both routes reach a monitored queue.

We do not currently publish a PGP key or operate a dedicated security mailbox. If your report contains material you are unwilling to send in plaintext, say so in your first message without the details and we will arrange an encrypted channel before you send anything further.

2. What is in scope

The GhostAnalyst marketing site (ghostanalyst.ai), the platform API (api.ghostanalyst.ai), the analyst and SOC consoles and per-tenant subdomains, the identity service (id.ghostanalyst.ai), and the Sovereign Sidecar collector distributed to customers.

Out of scope: findings that require physical access to a customer's premises; social engineering of our staff or customers; volumetric denial-of-service; reports generated solely by an automated scanner with no demonstrated impact; and vulnerabilities in third-party services we consume, which should go to that vendor.

3. What to include

The affected URL, endpoint, or component; the steps to reproduce; what an attacker gains; and any proof-of-concept you are willing to share. A clear reproduction is the single thing that most shortens the time to a fix.

4. What we ask of you

Give us a reasonable opportunity to remediate before disclosing publicly. Do not access, modify, or retain data belonging to another customer — if you encounter customer data while testing, stop and tell us what you saw so we can assess the exposure. Do not degrade service for others: test against your own tenant or trial account, never against another organisation's.

5. What we commit to

We aim to acknowledge every report within two business days, to tell you whether we consider it valid and roughly when we expect to fix it, and to keep you informed until it is closed. Where a report affects customers, our incident response follows the published service level commitments.

We will credit you by name in our release notes if you would like that, and will keep you anonymous if you would prefer. GhostAnalyst does not operate a paid bug bounty programme, and we would rather say so plainly than let you spend time on the assumption that one exists.

6. Customer-reported issues

If you are an existing customer and the issue affects your own tenant, raise it through your support channel as well, so it is tracked against your account and picked up under your SLA tier.