I'd leave that out unless you're confident the company isn't going to screw you. Speaking from experience.
I'd leave that out unless you're confident the company isn't going to screw you. Speaking from experience.
Sending a company proof that you've accessed a security hole (e.g. demonstrating it to them) can and has been prosecuted against has a hacking attempt and/or unauthorized access.
This is something every security researcher should know, and not necessarily pejorative against Nexmo in particular.
The parent was offering general advice for working with companies, and I was offering a general observation about that advice (namely, don't admit to technically-a-crime unless you know you're working with someone in good faith). Nothing personal, and it sounds like you guys have handled things professionally :-)
Edit: In particular and to clarify, my negative experience was not with your company.