Security Vulnerability Disclosure Policy
Purpose and scope
NEXT Fractional, Inc. (“NEXT Fractional,” “we,” “us”) provides fractional executive leadership and business growth services to enterprise and growth-stage clients. This policy establishes our vulnerability disclosure program in accordance with ISO/IEC 29147:2018 (vulnerability disclosure) and ISO/IEC 30111:2019 (vulnerability handling processes).
This policy applies to all systems, software, and digital infrastructure owned or operated by NEXT Fractional, including platforms operated on behalf of our partners and clients.
- NEXT Fractional web applications and APIs
- Call center and sales platform systems
- Customer data handling infrastructure
- Authentication and access control systems
- Partner-facing portals and integrations
- Cloud infrastructure and storage
- Third-party systems not owned by us
- Social engineering or phishing attacks
- Physical security vulnerabilities
- Denial of service (DoS/DDoS) attacks
- Systems of our vendors or partners
- Previously reported or known issues
What to report
We welcome responsible reports of any genuine security vulnerability. Examples of reportable issues include:
- Authentication or authorization flaws that could allow unauthorized access to customer or subscriber data
- Injection vulnerabilities (SQL, command, LDAP, etc.) in our applications or APIs
- Cross-site scripting (XSS), cross-site request forgery (CSRF), or server-side request forgery (SSRF)
- Exposure of sensitive data, including personal information, credentials, or payment card data
- Cryptographic weaknesses or improper use of encryption in data storage or transmission
- Insecure direct object references or broken access controls
- Misconfigured cloud storage, servers, or services exposing non-public data
- Security misconfigurations in our infrastructure that could lead to unauthorized access
| Severity | Description | Target response |
|---|---|---|
| Critical | Immediate risk of data breach, unauthorized access to subscriber PII, or system compromise | Patch within 7 days |
| High | Significant risk to data integrity, confidentiality, or system availability | Patch within 30 days |
| Medium | Limited impact or requires specific conditions to exploit | Patch within 60 days |
| Low | Minimal impact; informational or requires chained exploits | Patch within 90 days |
How to report
Submit vulnerability reports by email to [email protected]. To help us triage your report quickly, please include the following information:
- A description of the vulnerability and its potential impact
- The affected system, URL, or component
- Step-by-step reproduction instructions
- Proof-of-concept code, screenshots, or supporting evidence
- Your assessment of severity (Critical / High / Medium / Low)
- Your contact information and preferred communication method
What we commit to you
We value responsible security research and commit to the following when we receive your report:
We will not take legal action against researchers who discover and report vulnerabilities in good faith and in accordance with this policy. We will work cooperatively with you throughout the process and, with your permission, acknowledge your contribution publicly.
Coordinated disclosure timeline
We follow a coordinated vulnerability disclosure (CVD) model consistent with ISO/IEC 29147. Our default disclosure timeline is 90 days from the date we confirm receipt and validate your report.
Vulnerability handling process (ISO/IEC 30111)
Our internal vulnerability handling process follows the workflow prescribed by ISO/IEC 30111:2019. This standard governs how we receive, triage, resolve, and disclose security vulnerabilities across our organization.
- Receive: All reports are logged in our security tracking system and assigned a unique identifier. A designated security contact is assigned within 24 hours.
- Triage: Our security team validates the report, assigns a CVSS-based severity score, and determines whether the issue is in scope and reproducible.
- Investigate: We assess the root cause, identify affected systems and data, and determine the scope of any potential impact on customers or partners.
- Remediate: We develop, test, and deploy a patch or mitigating control. For critical issues, we implement interim mitigations while a permanent fix is developed.
- Notify: Where applicable, we notify affected parties, regulators, or downstream partners in accordance with contractual obligations and applicable law.
- Disclose: We coordinate public disclosure with the reporting researcher per the timeline above and issue a security advisory if warranted.
- Review: Post-resolution, we conduct a root-cause analysis and update our security controls to prevent recurrence.
Researcher safe harbor
NEXT Fractional supports responsible security research. We will not pursue civil or criminal action against researchers who comply with this policy. Safe harbor applies when you:
- Report the vulnerability promptly and do not exploit it beyond what is necessary to demonstrate the issue
- Do not access, modify, destroy, or exfiltrate customer data, personal information, or any data beyond what is minimally necessary to confirm the vulnerability
- Do not perform denial-of-service attacks, spam, or social engineering
- Do not publicly disclose the vulnerability before the agreed coordinated disclosure date
- Do not violate any applicable laws beyond those technically necessary to conduct the research
- Act in good faith throughout the disclosure and remediation process
Out-of-scope activities
The following activities are explicitly out of scope and may result in legal action regardless of intent:
- Accessing, downloading, or modifying real customer or subscriber personal information beyond confirming a vulnerability exists
- Performing denial-of-service (DoS) or distributed denial-of-service (DDoS) testing against our systems
- Social engineering, phishing, or vishing attacks targeting our employees, personnel, or customers
- Physical attacks against our offices, data centers, or personnel
- Submitting reports generated by automated vulnerability scanners without human validation
- Testing third-party systems, services, or infrastructure not owned or operated by NEXT Fractional
- Disclosing vulnerabilities publicly before the coordinated disclosure date without written consent
Questions about this policy: [email protected]
This policy is reviewed annually. Last reviewed: May 2026.
ISO/IEC 29147:2018 — Vulnerability disclosure
Security Vulnerability Disclosure Policy
Purpose and scope
NEXT Ventures, LLC (“NEXT Ventures,” “we,” “us”) operates digital marketing and sales platforms serving consumers and enterprise partners. This policy establishes our vulnerability disclosure program in accordance with ISO/IEC 29147:2018 (vulnerability disclosure) and ISO/IEC 30111:2019 (vulnerability handling processes).
This policy applies to all systems, software, and digital infrastructure owned or operated by NEXT Ventures, including platforms operated on behalf of our partners and clients.
- NEXT Ventures web applications and APIs
- Call center and sales platform systems
- Customer data handling infrastructure
- Authentication and access control systems
- Partner-facing portals and integrations
- Cloud infrastructure and storage
- Third-party systems not owned by us
- Social engineering or phishing attacks
- Physical security vulnerabilities
- Denial of service (DoS/DDoS) attacks
- Systems of our vendors or partners
- Previously reported or known issues
What to report
We welcome responsible reports of any genuine security vulnerability. Examples of reportable issues include:
- Authentication or authorization flaws that could allow unauthorized access to customer or subscriber data
- Injection vulnerabilities (SQL, command, LDAP, etc.) in our applications or APIs
- Cross-site scripting (XSS), cross-site request forgery (CSRF), or server-side request forgery (SSRF)
- Exposure of sensitive data, including personal information, credentials, or payment card data
- Cryptographic weaknesses or improper use of encryption in data storage or transmission
- Insecure direct object references or broken access controls
- Misconfigured cloud storage, servers, or services exposing non-public data
- Security misconfigurations in our infrastructure that could lead to unauthorized access
| Severity | Description | Target response |
|---|---|---|
| Critical | Immediate risk of data breach, unauthorized access to subscriber PII, or system compromise | Patch within 7 days |
| High | Significant risk to data integrity, confidentiality, or system availability | Patch within 30 days |
| Medium | Limited impact or requires specific conditions to exploit | Patch within 60 days |
| Low | Minimal impact; informational or requires chained exploits | Patch within 90 days |
How to report
Submit vulnerability reports by email to [email protected]. To help us triage your report quickly, please include the following information:
- A description of the vulnerability and its potential impact
- The affected system, URL, or component
- Step-by-step reproduction instructions
- Proof-of-concept code, screenshots, or supporting evidence
- Your assessment of severity (Critical / High / Medium / Low)
- Your contact information and preferred communication method
What we commit to you
We value responsible security research and commit to the following when we receive your report:
We will not take legal action against researchers who discover and report vulnerabilities in good faith and in accordance with this policy. We will work cooperatively with you throughout the process and, with your permission, acknowledge your contribution publicly.
Coordinated disclosure timeline
We follow a coordinated vulnerability disclosure (CVD) model consistent with ISO/IEC 29147. Our default disclosure timeline is 90 days from the date we confirm receipt and validate your report.
Vulnerability handling process (ISO/IEC 30111)
Our internal vulnerability handling process follows the workflow prescribed by ISO/IEC 30111:2019. This standard governs how we receive, triage, resolve, and disclose security vulnerabilities across our organization.
- Receive: All reports are logged in our security tracking system and assigned a unique identifier. A designated security contact is assigned within 24 hours.
- Triage: Our security team validates the report, assigns a CVSS-based severity score, and determines whether the issue is in scope and reproducible.
- Investigate: We assess the root cause, identify affected systems and data, and determine the scope of any potential impact on customers or partners.
- Remediate: We develop, test, and deploy a patch or mitigating control. For critical issues, we implement interim mitigations while a permanent fix is developed.
- Notify: Where applicable, we notify affected parties, regulators, or downstream partners in accordance with contractual obligations (including T-Mobile notification requirements under our affiliate agreement) and applicable law.
- Disclose: We coordinate public disclosure with the reporting researcher per the timeline above and issue a security advisory if warranted.
- Review: Post-resolution, we conduct a root-cause analysis and update our security controls to prevent recurrence.
Researcher safe harbor
NEXT Ventures supports responsible security research. We will not pursue civil or criminal action against researchers who comply with this policy. Safe harbor applies when you:
- Report the vulnerability promptly and do not exploit it beyond what is necessary to demonstrate the issue
- Do not access, modify, destroy, or exfiltrate customer data, personal information, or any data beyond what is minimally necessary to confirm the vulnerability
- Do not perform denial-of-service attacks, spam, or social engineering
- Do not publicly disclose the vulnerability before the agreed coordinated disclosure date
- Do not violate any applicable laws beyond those technically necessary to conduct the research
- Act in good faith throughout the disclosure and remediation process
Out-of-scope activities
The following activities are explicitly out of scope and may result in legal action regardless of intent:
- Accessing, downloading, or modifying real customer or subscriber personal information beyond confirming a vulnerability exists
- Performing denial-of-service (DoS) or distributed denial-of-service (DDoS) testing against our systems
- Social engineering, phishing, or vishing attacks targeting our employees, personnel, or customers
- Physical attacks against our offices, data centers, or personnel
- Submitting reports generated by automated vulnerability scanners without human validation
- Testing third-party systems, services, or infrastructure not owned or operated by NEXT Ventures
- Disclosing vulnerabilities publicly before the coordinated disclosure date without written consent
Questions about this policy: [email protected]
This policy is reviewed annually. Last reviewed: May 2026.
ISO/IEC 29147:2018 — Vulnerability disclosure
T-Mobile Exhibit E — Data Privacy and Protection Requirements
Every client gets real attention, direct access, and an executive who’s actually in the work. If the fit is right, we move fast.
© Copyright 2026 – NEXT Fractional, Inc. All rights reserved. | Security
