Version 1.0 · Effective 18 September 2026
Found a hole? Write to security@nerds.boutique. You will hear back from a person within three working days, and we will not come after you for looking.
The English version is the one that applies; translations are provided for convenience. See also our Privacy Policy and our list of subprocessors.
Email security@nerds.boutique with enough detail to reproduce the problem: the request, the response, and what you expected instead. A short screen recording beats a long description.
We answer within three working days — an actual answer, not a receipt. If the report is valid we will tell you what we are doing about it and when it is fixed.
Please do not go further than you need to. One record is proof enough; downloading somebody else’s data to demonstrate that you can is not research, and it changes our answer.
If you follow this page in good faith, we will not pursue you, will not report you, and will treat your testing as authorised. If a third party brings a claim about research that stayed within these rules, we will say so on your behalf.
Good faith means: your own account, your own data, no denial of service, no attempt to reach anybody else’s information beyond what proves the point, and time for us to fix the problem before you publish.
This website, our API at esim-be.nerds.boutique, and our mobile apps. Problems in our suppliers’ systems belong to them, but tell us anyway — we will pass it on and chase it.
Denial of service and load testing, social engineering of our people or our customers, physical access, and reports that consist of scanner output with no demonstrated impact. Missing best-practice headers on their own are not a vulnerability; show us what they let somebody do.
We do not pay for reports today. We would rather say that plainly than imply a programme we do not run. What we do promise: a real answer, a fix, and your name on this page if you want it.