Site information

Vulnerability disclosure policy

This is the page linked from /.well-known/security.txt (RFC 9116). We take security reports seriously and will work with you in good faith to understand and resolve an issue.

Report to
security@novexapilot.com
Acknowledgement
Within 3 business days
Disclosure window
90 days

How to report, and what happens next

  1. Send the report

    Email security@novexapilot.com (placeholder — confirm this mailbox is real and monitored before launch) with a description of the issue, the steps to reproduce it, and its potential impact. Encrypt sensitive details if possible. Please do not open a public issue, ticket, or social-media post before we have had a chance to respond.

  2. We acknowledge it

    We will acknowledge a report within 3 business days.

  3. We assess it

    We will give you an assessment of the report and, where accepted, an estimated remediation timeline.

  4. We fix it inside the disclosure window

    We ask for a 90-day disclosure window from the date of your report before any public disclosure, to give us time to investigate and fix the issue — matching the window described in this product’s compliance documentation. We will tell you if we need more time and why.

  5. We credit you, if you want it

    We will credit researchers who report responsibly, if they would like to be credited.

Scope

In scope

  • The Novexa Pilot application and API at novexapilot.com and its subdomains.
  • The tracking snippet (np.js) itself.
  • Authentication, authorization and tenant-isolation issues.

Out of scope

  • Vulnerabilities in a customer’s own website that merely has the tracking snippet installed.
  • Denial-of-service testing, spam, and social engineering against staff or customers.
  • Automated scanning that generates significant traffic without prior coordination.
  • Reports with no working proof of concept, or findings requiring physical access to a device.

Safe harbor

We will not pursue legal action against a good-faith researcher who follows this policy — stays within scope, avoids privacy violations and service disruption, and reports through the channel above rather than exploiting or publicly disclosing the issue first.

Placeholder — the exact legal language for this commitment should be reviewed by counsel before publication.

    Vulnerability disclosure · Novexa Pilot