PaperNest resources
Security & Vulnerability Reporting
Last updated: 9 October 2026
Help protect researcher accounts, confidential manuscripts, and journal and conference operations.
Protect your account
Use a strong, unique password and protect the email account you use for recovery. Sign out of shared devices and never share credentials or sign-in links. Staff access must be granted through the authorized role process; a colleague’s account should not be used as a substitute.
Research information handling
Unpublished manuscripts, private review material, and participant records belong in authorized workflows. Use the platform’s permitted file-access paths rather than public sharing links. Access depends on your relationship to a submission, the venue, and assigned responsibilities. Contact support if you encounter information you should not be able to see.
Report a vulnerability
Email the contact below with the subject “PaperNest security report”. Include the affected URL or feature, a concise description, minimal reproduction steps, expected versus observed behavior, and the potential impact. Redact credentials and personal or manuscript content from screenshots. If sensitive evidence is needed, first ask support for a suitable transfer method.
Responsible investigation
Use your own account and data, or obtain explicit permission for testing. Stop once you have enough evidence to describe the issue. Do not access other researchers’ files, alter records, interrupt availability, run bulk attacks, or disclose private information. Coordinate disclosure with the team so affected users can be protected. This page does not authorize intrusive testing or establish a bug-bounty reward.
Suspected account compromise
Reset your password using account recovery, secure your email account, and contact support with the affected account and approximate time. If a confidential manuscript or review may have been exposed, identify the venue and submission reference without attaching the research to the initial report.
Institutional security enquiries
Institutions can request deployment-specific information about access control, hosting, providers, recovery, and incident handling. No ISO, SOC, penetration-test, data-residency, or uptime certification is asserted by this page. Any formal assurance or service commitment must be supplied and agreed for the actual deployment.
Contact
For security concerns and responsible vulnerability reports, email media.brainfoundation@gmail.com.