Security Policy
Last updated: August 31, 2026
Nlitesoft d.o.o. takes the security of NTLite and ntlite.com seriously. This page explains how to report a vulnerability and what happens after you do.
Reporting a Vulnerability
If you believe you have found a security vulnerability in the NTLite software or in ntlite.com services, email [email protected]. Please do not post security issues on the public forum or social media before a fix is available.
Include what you can of the following: the software version or URL affected, steps to reproduce, the impact you believe it has, and any proof-of-concept material. If email does not work for you, the contact form works as well - mention that it concerns security so it gets routed correctly.
What to Expect
We aim to acknowledge your report within 7 days and will keep you informed as we validate and address the issue. Confirmed vulnerabilities are fixed with priority, and security fixes are released as soon as they are ready rather than waiting for a feature release.
If you would like credit for the discovery, tell us how you want to be named and we will include it in the release notes for the fix. If you prefer to stay anonymous, that is fine too.
Coordinated Disclosure
We ask that you keep the details of a report private until a fixed version is available to users. In return, we work with you on a disclosure timeline, and once a fix has shipped we publish information about the vulnerability - a description, the affected versions, its severity, and how to remediate - in the changelog.
Good-Faith Research
We will not pursue legal action against researchers who report vulnerabilities in good faith: testing done without harming users or data, without degrading our services, and without accessing data that is not yours. Automated scanning that disrupts services, spam, social engineering of our staff or users, and physical attacks are outside the scope of this policy.
Scope
In scope: the NTLite software (all versions and channels), its update mechanism, and the ntlite.com website and services. Out of scope: vulnerabilities in Windows itself or other Microsoft components NTLite operates on (report those to Microsoft), and issues in third-party services we use, such as the payment processor (report those to the vendor).
Software Update Security
NTLite downloads are served over HTTPS and installers are digitally signed. The built-in updater verifies the digital signature of a downloaded update before installing it and refuses files that fail verification. If the software ever reports an update signature problem, do not run the file manually - report it to [email protected].