Security Policy
Nyx Backup Version: 1 Last updated: 2026-07-31 Effective: 2026-07-31 Nyx Software, LLC security@nyxbackup.com Documentation and support: https://nyxbackup.com/support
Reporting a vulnerability
Email security@nyxbackup.com. Include the affected version and platform, how to reproduce it, and your view of the impact.
Credit. We publish advisories at https://nyxbackup.com/security/advisories and name the person who reported each issue. If you want to be credited, tell us the exact name or handle to use, and a link if you would like one. If you would rather not be named, say so and we will publish the advisory without attribution. Either way we will thank you directly.
| Stage | Target |
|---|---|
| Acknowledgement | 2 business days |
| Triage and severity | 5 business days |
| Updates after that | Every 14 days until resolved |
| Fix or documented mitigation | 90 days from triage, target |
| Public advisory | On fix release, or at 90 days |
| Where advisories appear | https://nyxbackup.com/security/advisories |
We prefer coordinated disclosure at 90 days and will tell you promptly if a fix needs longer and why. We will not ask you to stay quiet indefinitely.
We do not pay bug bounties. Credit in a published advisory is what we can offer, and we give it by default.
Safe harbor
If you research in good faith under this policy, we will treat your work as authorized, we will not pursue or support legal action against you, and if a third party comes after you for it we will make that authorization known. The Terms of Service ban on probing and scanning does not apply to research under this policy.
Good faith means: report promptly, do not access, change, or take data that is not yours, do not degrade service for other people, do not run heavy automated scanning, no social engineering or physical attacks, and give us the time above before going public.
In scope
The desktop application, the license service and machine-check endpoint, the telemetry endpoint, nyxbackup.com, and our installers and signing chain.
Out of scope
Storage providers (report to them), Paddle’s checkout (report to Paddle), anything requiring the attacker to already have admin control of the machine or the user’s passphrase, missing hardening headers with no demonstrated impact, unvalidated scanner output, and volumetric denial of service.
How the product is built
These are commitments about our engineering, not warranties, and are subject to EULA sections 7 and 8.
- Backup data is end-to-end encrypted with keys derived on your machine. We cannot decrypt it and cannot recover it.
- License verification is a signed-file check performed entirely offline.
- Credentials, OAuth tokens, and the master key live in the OS keyring, never in config files.
- Releases are code-signed.
- We generate a software bill of materials (SBOM) for every release and monitor those components for known vulnerabilities.
- Security and critical bug fixes are free for the full 24-month support period, whether or not the update window is still open.