Norvaile

Security

Responsible disclosure

Found a vulnerability in one of our systems? Report it to us. We will work with you to resolve it quickly and openly.

We take security seriously

Norvaile is committed to keeping its systems and customers safe. If you have found a vulnerability, we want to hear from you. Together we can fix it before others can misuse it.

How to report

Send your findings by email to security@norvaile.com with the following information:

  • A clear description of the vulnerability and its impact.
  • Steps to reproduce, including any URLs, parameters, or payloads used.
  • Your name and how we can reach you (for follow-up questions).
  • The date and time of the finding.

For sensitive information, request our PGP key by email and we will send it back.

Our commitment

  • We will acknowledge your report within three working days.
  • We will keep you informed of progress at least every two weeks.
  • We will investigate valid findings and work on a fix as quickly as possible.
  • We will credit you in our public hall of fame, if you wish.

What we ask of you

  • Do not exploit the vulnerability beyond what is strictly necessary to demonstrate it.
  • Do not access, modify, retain, or transfer data belonging to others.
  • Do not publicly disclose the vulnerability before we have had a chance to fix it.
  • Do not use social engineering, phishing, or denial-of-service techniques.

Out of scope

Findings without a real security impact (such as missing security headers on static pages, descriptive error messages without data exposure, and rate limiting on non-sensitive forms) are not in scope. Self-XSS, clickjacking on pages without sensitive actions, and similar low-impact issues are also out of scope.

Safe harbour

If you act in good faith and follow this policy, Norvaile will not take legal action against you and will work with you to resolve the issue. We appreciate your effort to help us keep our systems safe.

Want to work with us on security?

We are always looking for skilled security researchers. Reach out and let us know what you can bring.