PaperNest resources

Security & Vulnerability Reporting

Last updated: 9 October 2026

Help protect researcher accounts, confidential manuscripts, and journal and conference operations.

Protect your account

Use a strong, unique password and protect the email account you use for recovery. Sign out of shared devices and never share credentials or sign-in links. Staff access must be granted through the authorized role process; a colleague’s account should not be used as a substitute.

Research information handling

Unpublished manuscripts, private review material, and participant records belong in authorized workflows. Use the platform’s permitted file-access paths rather than public sharing links. Access depends on your relationship to a submission, the venue, and assigned responsibilities. Contact support if you encounter information you should not be able to see.

Report a vulnerability

Email the contact below with the subject “PaperNest security report”. Include the affected URL or feature, a concise description, minimal reproduction steps, expected versus observed behavior, and the potential impact. Redact credentials and personal or manuscript content from screenshots. If sensitive evidence is needed, first ask support for a suitable transfer method.

Responsible investigation

Use your own account and data, or obtain explicit permission for testing. Stop once you have enough evidence to describe the issue. Do not access other researchers’ files, alter records, interrupt availability, run bulk attacks, or disclose private information. Coordinate disclosure with the team so affected users can be protected. This page does not authorize intrusive testing or establish a bug-bounty reward.

Suspected account compromise

Reset your password using account recovery, secure your email account, and contact support with the affected account and approximate time. If a confidential manuscript or review may have been exposed, identify the venue and submission reference without attaching the research to the initial report.

Institutional security enquiries

Institutions can request deployment-specific information about access control, hosting, providers, recovery, and incident handling. No ISO, SOC, penetration-test, data-residency, or uptime certification is asserted by this page. Any formal assurance or service commitment must be supplied and agreed for the actual deployment.

Contact

For security concerns and responsible vulnerability reports, email media.brainfoundation@gmail.com.