PRODUCT SECURITY

Report a security issue

Security reports concerning Nimbus Driver Studio and its supporting infrastructure are received at the address below. The contact is not exclusively automated.

Product Security Contact

security@pacificmindworks.com is the single point of contact for reports.

Reports may also be sent by post to:

Pacific MindWorks, Product Security
1250 S Capital of Texas Highway, Building 3, Suite 400
Austin, TX 78746, United States

Do not include unnecessary personal data or confidential information unrelated to the report. For bulky proof-of-concept material or sensitive attachments, contact us first to arrange a secure transfer method.

What is in scope

This page covers Nimbus Driver Studio, the web-based license server used to validate entitlements, and the redistributable component embedded in customers' own installers, together with the software, repositories, build and release arrangements, signing infrastructure and distribution channels controlled by Pacific MindWorks. Reports may concern integrated third-party or open-source components.

This page does not promise continuous 24/7 monitoring, a hotline, a security operations center or a bug-bounty program.

What to include

The following information assists assessment. It is requested where available, not required; incomplete reports are accepted, and further information may be requested.

  • Affected offering, component, service or version. Nimbus Driver Studio and its version, the license server, or the redistributable component, as applicable.
  • The suspected vulnerability, its potential impact and the affected environment. The nature of the weakness, what exploitation would affect in terms of confidentiality, integrity, availability or authenticity, and the environment in which it occurs.
  • Reproduction steps, proof of concept, logs or other supporting evidence. Bulky material as an attachment rather than in the body of a message.
  • Evidence or reasonable suspicion of active exploitation. None known, suspected or confirmed, and the evidence relied on. This determines triage; an answer is requested in either case.
  • Reporter contact method or pseudonym. For follow-up questions, and to state whether attribution in a security advisory is wanted.
  • Third-party or open-source components involved. Name of the component, and whether it has already been reported to its maintainer or supplier.

Case reference, receipt time and intake channel are recorded by Pacific MindWorks and are not to be supplied by the reporter. Reports made in good faith are handled confidentially to the extent reasonably possible.

How a report is handled

  • Acknowledgment – without undue delay where practicable, with a case file opened. An acknowledgment does not confirm the existence, severity, exploitability or legal significance of the matter.
  • Triage and validation – proportionate reproduction and validation. Information needed to assess the matter may be requested, and material status updates are given where practicable.
  • Remediation – risk-based, and verified before release. Security updates are provided free of charge during the applicable support period and, where technically feasible, separately from feature updates.
  • Disclosure – coordinated, with an ordinary target of 90 days from acknowledgment. A security advisory follows once a fix or sufficient mitigation is available.

This process is governed by the Pacific MindWorks Coordinated Vulnerability Disclosure Policy, effective September 9, 2026. Machine-readable contact: security.txt. Language: English.

Customers who redistribute

Where a security update affects the redistributable component embedded in a customer's own installer, affected customers may be instructed to rebuild and redistribute their installers using the updated component. Such notices are sent through the customer relationship, not only through this page.

Good-faith research

Research should avoid data exfiltration, unnecessary service disruption, privacy violations, social engineering, destruction or alteration of data, and access beyond what is necessary to demonstrate a suspected vulnerability. The contact above should be used before public disclosure of non-public technical details.

This expresses limited safe harbor expectations for research conduct only. It does not create a legally binding safe harbor, bug-bounty or reward program, and it does not alter any legal rights or obligations.

Matters that are not security reports

Licensing questions, installation problems, build errors and other defects are handled at support@pacificmindworks.com. Matters sent to the security address that are not security matters are forwarded there, with notice to the sender.

Page version 1.0 · last reviewed September 11, 2026 · reviewed at least annually

Our privacy policy tells you about the information we collect from you, why and how we use your data, and the rights you have over this data. It also explains our use of cookies. Read our policy