About Nydra Research


Nydra Research is the public and social-interest research branch of Nydra. We operate under an open-access and non-commercial model, with two distinct editorial lines, each with its own standard of rigor.

1. Investigation and Verification

We analyze topics of public interest where we detect misinformation, widespread ignorance, or lack of accessible context: public policy and digital regulation, security dynamics and organized crime at a pattern level (never identified individuals without a solid public basis), geopolitics when it directly touches Mexico, and other topics where separating verified facts from rumor adds real value.

In these texts, we explicitly distinguish between what is confirmed by direct sources, what is a reasoned interpretation based on indirect evidence, and what remains unverified — we never present the second or third as if they were the first.

2. Technical Audit and Privacy

We assess the code, scripts, and data policies of applications, websites, and institutions in a passive and non-intrusive way to identify vulnerabilities or non-transparent data collection practices — both to help the responsible organization fix it, and to let the public know what is happening with their information.

Responsible Disclosure Policy

When we identify a vulnerability or security flaw in a third-party system, we follow the same 90+30 day policy used by Google's Project Zero:

  • Upon confirming the finding, we privately notify the responsible team with the technical detail necessary to reproduce and fix it. That day marks the start of the timeline.
  • The responsible team has 90 days to make a patch available to users.
  • If the patch arrives within those 90 days, we publish the details of the finding 30 days after the patch is available — not before.
  • If the responsible team fails to patch in 90 days but can do so within an additional 14 days (i.e., before day 104), they may request a grace period from us. In that case, we publish the details on day 120 counted from the initial notification.
  • If there is no patch and no grace period requested, we publish the details at the close of day 90.
  • If the issue is already being actively exploited or represents an imminent risk to the public, we may shorten these timelines and publish earlier, prioritizing the security of affected users.
  • Upon publication, we document the complete timeline: notification date, patch date (if any), and public disclosure date.

Correction and collaboration

We care that what we publish is accurate. If you find an error, outdated information, or an inaccuracy in any of our articles, write to us and we will review it: when appropriate, we publish a visible correction in the original text with the date of the adjustment, without hiding that there was a change.

We also welcome contributions from researchers, developers, or anyone with additional information that can expand, nuance, or contextualize what we have already published. We do not guarantee to publish everything we receive, but we do review every contribution seriously before deciding.

Common principles

We do not perform unauthorized access, denial of service, or active interception. All analysis starts from public artifacts, accessible documentation, or information that any analyst can legally inspect. For corrections, collaborations, vulnerability reports, or any questions, write to us at research@nydra.org.