Security and Vulnerability Disclosure
We welcome reports from people who find security issues in our website. This page explains how we protect it and how to report a vulnerability.
Last updated: September 13, 2026
How we protect the website
- Encrypted connections (HTTPS with HSTS) and a strict Content Security Policy
- Server-side verification, rate limits, and duplicate protection on the inquiry form
- Minimal data collection and restricted access to the systems that process it
- Regular updates and a firewall that exposes only the services the website needs
Reporting a vulnerability
Email us using the address below with the subject “Security report.” Please include a description of the issue, the affected URL, steps to reproduce it, and its potential impact.
Guidelines
- Act in good faith and avoid privacy violations, data destruction, and service disruption
- Access only the minimum data needed to show the issue, and do not keep it
- Do not use denial-of-service, spam, social engineering, or physical attacks
- Give us reasonable time to fix the issue before disclosing it publicly
Scope
This policy covers nrcosolutions.com. Report issues in third-party services we use, such as Google or Cloudflare, to those providers. We do not currently offer a bug bounty.
Our commitment
We will review reports, keep you informed of our progress, and credit you if you wish once the issue is fixed. We will not pursue legal action against research carried out in good faith and in line with this policy.
A machine-readable summary is available at /.well-known/security.txt.
