Security
Effective: 1 November 2026
Report a vulnerability
If you think you've found a security problem in Nia, please email security@niaspark.com with the steps to reproduce it and what an attacker could do with it. We'll reply within 5 working days and keep you updated until it's fixed.
While you look into it, please:
- only test against your own account and data
- don't access, change or delete other people's data. Stop and tell us if you come across any.
- don't run denial-of-service, spam or social-engineering tests
- give us a reasonable time to fix the issue before you share it publicly
If you follow these rules in good faith, we won't take legal action against you over your research. There's no paid bug bounty yet, but we're happy to credit you once it's fixed.
How Nia protects your data
- Encrypted connections: all traffic to niaspark.com and its apps uses HTTPS.
- No passwords to leak: you sign in with Google, GitHub, Microsoft, Discord, Spotify or Slack, and we never see or store your password.
- Locked-down servers: databases and internal services aren't reachable from the internet, only from a private network.
- Your data is yours: every account's chats, notes, tasks and events are kept separate, and each request is checked against the signed-in user.
- Approval before risky actions: sending email, moving files, and controlling your computer or phone ask for your go-ahead first, unless you turn on auto-approval.
- Extra locks: you can lock chats and folders behind a PIN, and email addresses in conversations are masked before they're stored.
No system is perfectly secure. If a breach puts your data at risk, we'll tell you, as described in the Privacy Policy.