Security Policy

Nyx Backup Version: 1 Last updated: 2026-07-31 Effective: 2026-07-31 Nyx Software, LLC security@nyxbackup.com Documentation and support: https://nyxbackup.com/support

Reporting a vulnerability

Email security@nyxbackup.com. Include the affected version and platform, how to reproduce it, and your view of the impact.

Credit. We publish advisories at https://nyxbackup.com/security/advisories and name the person who reported each issue. If you want to be credited, tell us the exact name or handle to use, and a link if you would like one. If you would rather not be named, say so and we will publish the advisory without attribution. Either way we will thank you directly.

StageTarget
Acknowledgement2 business days
Triage and severity5 business days
Updates after thatEvery 14 days until resolved
Fix or documented mitigation90 days from triage, target
Public advisoryOn fix release, or at 90 days
Where advisories appearhttps://nyxbackup.com/security/advisories

We prefer coordinated disclosure at 90 days and will tell you promptly if a fix needs longer and why. We will not ask you to stay quiet indefinitely.

We do not pay bug bounties. Credit in a published advisory is what we can offer, and we give it by default.

Safe harbor

If you research in good faith under this policy, we will treat your work as authorized, we will not pursue or support legal action against you, and if a third party comes after you for it we will make that authorization known. The Terms of Service ban on probing and scanning does not apply to research under this policy.

Good faith means: report promptly, do not access, change, or take data that is not yours, do not degrade service for other people, do not run heavy automated scanning, no social engineering or physical attacks, and give us the time above before going public.

In scope

The desktop application, the license service and machine-check endpoint, the telemetry endpoint, nyxbackup.com, and our installers and signing chain.

Out of scope

Storage providers (report to them), Paddle’s checkout (report to Paddle), anything requiring the attacker to already have admin control of the machine or the user’s passphrase, missing hardening headers with no demonstrated impact, unvalidated scanner output, and volumetric denial of service.

How the product is built

These are commitments about our engineering, not warranties, and are subject to EULA sections 7 and 8.

  • Backup data is end-to-end encrypted with keys derived on your machine. We cannot decrypt it and cannot recover it.
  • License verification is a signed-file check performed entirely offline.
  • Credentials, OAuth tokens, and the master key live in the OS keyring, never in config files.
  • Releases are code-signed.
  • We generate a software bill of materials (SBOM) for every release and monitor those components for known vulnerabilities.
  • Security and critical bug fixes are free for the full 24-month support period, whether or not the update window is still open.

Published security advisories