Responsible Disclosure Policy

Data security is a top priority for Novara Software, LLC and we believe that working with skilled security researchers can identify weaknesses in any technology. Publicly disclosing a security vulnerability without informing us first puts the rest of the community at risk.

If you believe you’ve found a security vulnerability in Novara’s service, please notify us using the instructions in the disclosure process section and we will work with you to resolve the issue promptly.

We currently do not have an officially defined financial reward system “bug bounty program” in place. As such, compensation should not be expected after submission.

Safe Harbor

Novara Software, LLC will not initiate a lawsuit or law enforcement investigation against any researcher if they abide by the terms and conditions defined on this page along with our privacy policy. Any attempts at extortion such as blackmail, ransomware, threats, or any other illegal activities will violate the safe harbor agreement and may result in legal action.

Disclosure Process

If you believe you’ve discovered a potential vulnerability, please let us know by emailing [email protected]. Please provide us with a reasonable amount of time to resolve the issue before disclosing it to the public or third parties. We aim to resolve critical issues within 30 days of disclosure.

In-Scope Domains

Novara has multiple product offerings and corporate websites, the following domains (and subdomains) are within the scope of this responsible disclosure program.

In-Scope Vulnerabilities

Any design or implementation issue that substantially affects the confidentiality, integrity or availability of user data is likely to be in scope for this program. The list below are examples of vulnerabilities that should be submitted if found.

Out-of-Scope Vulnerabilities

Please do not submit any of the following unless you deem it to be a serious vulnerability.

Prohibited Actions

The following activities are strictly prohibited.