Nex Team Inc.
Found a security issue in one of our products? We want to know about it. Here's how we work together to keep families safe.
Published: February 2026
Last Updated: February 2026
This policy covers security vulnerabilities in any Nex product or service—from Nex Playground hardware to our apps, websites, and cloud services.
We genuinely appreciate security researchers who take the time to help us protect the families who trust our products. While we don't currently offer bug bounties or monetary rewards, we're committed to working with you respectfully and collaboratively.
Please read through this whole policy before submitting a report, and stick to these guidelines throughout the process.
If you think you've found a security vulnerability, here's how to reach us:
Online Report Form: [security.nexplayground.com/report] (update with actual URL)
Email: security@nex.com (update with actual address)
Help us help you—include these details:
The more information you give us up front, the faster we can validate the issue and get to work fixing it.
Within 5 business days: We'll confirm we got your report and give you a tracking reference number.
Within 10 business days: We'll finish our initial assessment and let you know if we've confirmed it's a real vulnerability.
Regular updates: We'll keep you in the loop on our progress. Some fixes are straightforward; others need deep investigation or complex engineering work. In some cases, proper remediation can take 90 days or longer—especially if we need to coordinate with hardware manufacturers, app store reviews, or update cycles that reach thousands of families.
Status check-ins: Feel free to ask how things are going, but please keep it to once every 14 days. This helps our security team stay focused on actually fixing the problem rather than writing status emails.
When it's fixed: We'll let you know when the vulnerability is resolved and may ask you to verify that our fix actually works.
Going public: Planning to write a blog post or publish your findings? Great! Just coordinate with us first so we can make sure affected families get clear, accurate information and aren't caught off guard.
We want security testing to be safe for everyone involved—you, our team, and especially the families using our products.
Please don't:
Please do:
This policy follows recognized best practices for coordinated vulnerability disclosure and meets UK Product Security and Telecommunications Infrastructure (PSTI) requirements.
Here's what this means for you:
This policy doesn't give you permission to do anything illegal or that would violate laws in your jurisdiction. You're responsible for making sure your security research is lawful where you live.
But here's what we'll do:
If you've followed this policy completely and in good faith, and someone tries to take legal action against you because of your vulnerability report, Nex will publicly confirm that you were acting in accordance with this policy.
We want reports about:
Please don't report these:
Security research is real work, and we respect that. When you report a vulnerability to us, we commit to:
Security Reports: security@nex.com (update this)
Data Protection Officer: dpo@nex.com (update this)
General Support: support@nexplayground.com (update this)
For non-security questions, please use our Help Center instead—it'll get you answers faster.
Company Details:
Nex Team Inc. ( HK or San Jose )
[Company Address]
[City, State/Province, Postal Code]
[Country]
Regulatory Compliance:
This policy supports our compliance with:
Thanks for helping us keep families safe.