Vulnerability Disclosure Policy
Last updated: 2026-05-21
We rely on the security community to help keep Noospera safe. This Policy explains how to report a vulnerability and what we commit to in return.
Scope
In scope:
- The Noospera web application at the production domain.
- The backend API (FastAPI) endpoints.
- Authentication, payment, and data-handling flows.
- Encryption-at-rest and access-control configurations within our control.
Out of scope:
- Third-party services we use (currently OpenAI, Privy, Stripe, Railway) — please report directly to them.
- Denial-of-service attacks against shared infrastructure.
- Social engineering of staff or users.
- Findings that require physical access to a user's device.
- Reports based solely on automated scanner output without a demonstrated impact.
How to report
Send a report to [email protected]. Include:
- A description of the issue and where it is.
- Steps to reproduce, with as much technical detail as you can provide.
- An assessment of impact.
- Your contact information and whether you wish to be credited.
What we commit to
- Acknowledge receipt within 3 business days.
- Provide an initial triage and severity assessment within 10 business days.
- Provide regular updates on remediation progress.
- Credit you in our changelog if you wish.
- Refrain from legal action against good-faith researchers who follow this Policy.
What we ask
- Do not access or modify data of users other than your own test accounts.
- Do not run automated scans that degrade the Service.
- Do not publicly disclose the vulnerability until we have had a reasonable opportunity to fix it (typically 90 days, sooner for critical issues).
- Do not extort, threaten, or demand compensation as a condition of disclosure.
Bug bounty
A formal bug bounty programme is not yet in place. Where impact warrants, we may offer a discretionary reward.