Responsible disclosure
How to report a security vulnerability to Noxys.
Scope
This policy covers noxys.eu, the Noxys API, the console and the browser extension. Please avoid testing that could affect other users' data or service availability.
How to report
- Send an encrypted report to [email protected]
- We acknowledge reports within 3 business days.
- We assess and triage the issue, keeping you informed.
- We coordinate disclosure timing with you once a fix is available.
PGP
Use our PGP key to encrypt sensitive reports:
-----BEGIN PGP PUBLIC KEY BLOCK----- [email protected] Replace with production key from security team before external audit. -----END PGP PUBLIC KEY BLOCK-----
Hall of Fame
| Researcher | Finding | Date |
|---|---|---|
| — | Be the first — we credit researchers who report valid issues. | — |