Site information
Vulnerability disclosure policy
This is the page linked from /.well-known/security.txt (RFC 9116). We take security reports seriously and will work with you in good faith to understand and resolve an issue.
- Report to
- security@novexapilot.com
- Acknowledgement
- Within 3 business days
- Disclosure window
- 90 days
DocumentsVulnerability disclosure
How to report, and what happens next
Send the report
Email
security@novexapilot.com(placeholder — confirm this mailbox is real and monitored before launch) with a description of the issue, the steps to reproduce it, and its potential impact. Encrypt sensitive details if possible. Please do not open a public issue, ticket, or social-media post before we have had a chance to respond.We acknowledge it
We will acknowledge a report within 3 business days.
We assess it
We will give you an assessment of the report and, where accepted, an estimated remediation timeline.
We fix it inside the disclosure window
We ask for a 90-day disclosure window from the date of your report before any public disclosure, to give us time to investigate and fix the issue — matching the window described in this product’s compliance documentation. We will tell you if we need more time and why.
We credit you, if you want it
We will credit researchers who report responsibly, if they would like to be credited.
Scope
In scope
- The Novexa Pilot application and API at novexapilot.com and its subdomains.
- The tracking snippet (
np.js) itself. - Authentication, authorization and tenant-isolation issues.
Out of scope
- Vulnerabilities in a customer’s own website that merely has the tracking snippet installed.
- Denial-of-service testing, spam, and social engineering against staff or customers.
- Automated scanning that generates significant traffic without prior coordination.
- Reports with no working proof of concept, or findings requiring physical access to a device.
Safe harbor
We will not pursue legal action against a good-faith researcher who follows this policy — stays within scope, avoids privacy violations and service disruption, and reports through the channel above rather than exploiting or publicly disclosing the issue first.
Placeholder — the exact legal language for this commitment should be reviewed by counsel before publication.
