NEXT Fractional, Inc.
Dallas, TX · nextfractional.com
Security Policy · Public

Security Vulnerability Disclosure Policy

We are committed to protecting the security of our systems and the privacy of our customers. This policy describes how to report security vulnerabilities responsibly and what you can expect from us in return.
Effective date01-May-2026
StandardISO/IEC 30111:2019 · ISO/IEC 29147:2018
Version1.0
Review cycleAnnual
Report a vulnerability
Please encrypt sensitive reports using our PGP key (available on request)
24-hr acknowledgment
01

Purpose and scope

NEXT Fractional, Inc. (“NEXT Fractional,” “we,” “us”) provides fractional executive leadership and business growth services to enterprise and growth-stage clients. This policy establishes our vulnerability disclosure program in accordance with ISO/IEC 29147:2018 (vulnerability disclosure) and ISO/IEC 30111:2019 (vulnerability handling processes).

This policy applies to all systems, software, and digital infrastructure owned or operated by NEXT Fractional, including platforms operated on behalf of our partners and clients.

In scope
  • NEXT Fractional web applications and APIs
  • Call center and sales platform systems
  • Customer data handling infrastructure
  • Authentication and access control systems
  • Partner-facing portals and integrations
  • Cloud infrastructure and storage
Out of scope
  • Third-party systems not owned by us
  • Social engineering or phishing attacks
  • Physical security vulnerabilities
  • Denial of service (DoS/DDoS) attacks
  • Systems of our vendors or partners
  • Previously reported or known issues
02

What to report

We welcome responsible reports of any genuine security vulnerability. Examples of reportable issues include:

  • Authentication or authorization flaws that could allow unauthorized access to customer or subscriber data
  • Injection vulnerabilities (SQL, command, LDAP, etc.) in our applications or APIs
  • Cross-site scripting (XSS), cross-site request forgery (CSRF), or server-side request forgery (SSRF)
  • Exposure of sensitive data, including personal information, credentials, or payment card data
  • Cryptographic weaknesses or improper use of encryption in data storage or transmission
  • Insecure direct object references or broken access controls
  • Misconfigured cloud storage, servers, or services exposing non-public data
  • Security misconfigurations in our infrastructure that could lead to unauthorized access
SeverityDescriptionTarget response
CriticalImmediate risk of data breach, unauthorized access to subscriber PII, or system compromisePatch within 7 days
HighSignificant risk to data integrity, confidentiality, or system availabilityPatch within 30 days
MediumLimited impact or requires specific conditions to exploitPatch within 60 days
LowMinimal impact; informational or requires chained exploitsPatch within 90 days
03

How to report

Submit vulnerability reports by email to [email protected]. To help us triage your report quickly, please include the following information:

  • A description of the vulnerability and its potential impact
  • The affected system, URL, or component
  • Step-by-step reproduction instructions
  • Proof-of-concept code, screenshots, or supporting evidence
  • Your assessment of severity (Critical / High / Medium / Low)
  • Your contact information and preferred communication method
Encrypting your report
If your report contains sensitive data — credentials, PII, or exploit details — please request our PGP public key before submitting. Email [email protected] with subject line “PGP Key Request” and we will respond within one business day.
04

What we commit to you

We value responsible security research and commit to the following when we receive your report:

Acknowledgment
Within 24 hours
We confirm receipt of your report and assign a tracking reference.
Initial assessment
Within 5 business days
We evaluate severity, impact, and whether the issue is reproducible.
Status updates
Every 14 days
We provide progress updates through resolution or disclosure.
Resolution notice
Upon remediation
We notify you when the vulnerability has been addressed.

We will not take legal action against researchers who discover and report vulnerabilities in good faith and in accordance with this policy. We will work cooperatively with you throughout the process and, with your permission, acknowledge your contribution publicly.

05

Coordinated disclosure timeline

We follow a coordinated vulnerability disclosure (CVD) model consistent with ISO/IEC 29147. Our default disclosure timeline is 90 days from the date we confirm receipt and validate your report.

Day 0
Report received
Acknowledgment sent within 24 hours. Tracking reference assigned.
Day 1–5
Triage and validation
We reproduce the issue, assess severity, and assign it to the appropriate internal team.
Day 6–60
Remediation development
We develop and test a fix. Updates provided to you every 14 days.
Day 60–90
Patch deployment and verification
Fix is deployed and we verify the issue is resolved in production.
Day 90
Coordinated public disclosure
We coordinate with you on any public advisory. If a patch isn’t ready, we discuss an extension.
Disclosure extensions
For complex vulnerabilities requiring additional remediation time, we may request an extension beyond 90 days. We will communicate this proactively and agree on a revised timeline with you in writing. We will not request an extension simply to delay disclosure — extensions are reserved for genuine remediation complexity or cases where early disclosure would pose a risk to customers.
06

Vulnerability handling process (ISO/IEC 30111)

Our internal vulnerability handling process follows the workflow prescribed by ISO/IEC 30111:2019. This standard governs how we receive, triage, resolve, and disclose security vulnerabilities across our organization.

  • Receive: All reports are logged in our security tracking system and assigned a unique identifier. A designated security contact is assigned within 24 hours.
  • Triage: Our security team validates the report, assigns a CVSS-based severity score, and determines whether the issue is in scope and reproducible.
  • Investigate: We assess the root cause, identify affected systems and data, and determine the scope of any potential impact on customers or partners.
  • Remediate: We develop, test, and deploy a patch or mitigating control. For critical issues, we implement interim mitigations while a permanent fix is developed.
  • Notify: Where applicable, we notify affected parties, regulators, or downstream partners in accordance with contractual obligations and applicable law.
  • Disclose: We coordinate public disclosure with the reporting researcher per the timeline above and issue a security advisory if warranted.
  • Review: Post-resolution, we conduct a root-cause analysis and update our security controls to prevent recurrence.
Partner and regulatory notification
Where a vulnerability results in unauthorized access to protected information, we notify affected clients and partners in accordance with our contractual obligations, and comply with applicable state breach notification laws and federal regulations. We will not delay notification to preserve disclosure coordination.
07

Researcher safe harbor

NEXT Fractional supports responsible security research. We will not pursue civil or criminal action against researchers who comply with this policy. Safe harbor applies when you:

  • Report the vulnerability promptly and do not exploit it beyond what is necessary to demonstrate the issue
  • Do not access, modify, destroy, or exfiltrate customer data, personal information, or any data beyond what is minimally necessary to confirm the vulnerability
  • Do not perform denial-of-service attacks, spam, or social engineering
  • Do not publicly disclose the vulnerability before the agreed coordinated disclosure date
  • Do not violate any applicable laws beyond those technically necessary to conduct the research
  • Act in good faith throughout the disclosure and remediation process
Note: Safe harbor does not apply to researchers who exploit vulnerabilities beyond validation, access or exfiltrate real customer or subscriber data, or fail to contact us before disclosure. We reserve the right to pursue legal remedies in such cases.
08

Out-of-scope activities

The following activities are explicitly out of scope and may result in legal action regardless of intent:

  • Accessing, downloading, or modifying real customer or subscriber personal information beyond confirming a vulnerability exists
  • Performing denial-of-service (DoS) or distributed denial-of-service (DDoS) testing against our systems
  • Social engineering, phishing, or vishing attacks targeting our employees, personnel, or customers
  • Physical attacks against our offices, data centers, or personnel
  • Submitting reports generated by automated vulnerability scanners without human validation
  • Testing third-party systems, services, or infrastructure not owned or operated by NEXT Fractional
  • Disclosing vulnerabilities publicly before the coordinated disclosure date without written consent

Every client gets real attention, direct access, and an executive who’s actually in the work. If the fit is right, we move fast.

© Copyright 2026 – NEXT Fractional, Inc. All rights reserved.  |  Security