How to report
One address, read by a person. There is no form to fill in and no account to create.
The same contact is published in our security.txt, per RFC 9116.
Scope
Stated plainly, because a policy that leaves scope vague pushes the researcher into guessing — and a wrong guess is how good-faith research turns into an incident.
Safe harbour
What you get from us if you act in good faith.
If you follow the scope above, act in good faith, avoid privacy violations and service disruption, and give us a reasonable opportunity to fix the issue before disclosing it publicly, then NOUSEC will not pursue or support legal action against you for your research.
If a third party brings action against you for research that stayed inside this policy, we will make it known that your work was authorised under it. If you want that commitment in writing before you start, ask and we will send it.
What we ask of you
Four rules, all of them about not turning a test into an incident.
What we do not claim
NOUSEC has not completed a SOC 2 or ISO/IEC 27001 audit. We hold no certification against either standard, and nothing on this site should be read as a certification claim. We have not commissioned an independent penetration test. When those things change, this page will say so, with a date.
Elsewhere on this site you will read that NOUSEC maps evidence per tenant to seven frameworks — KVKK, ISO/IEC 27001, NIS2, BDDK, SOC 2, GDPR and ISO/IEC 27701. That sentence describes what the product does with your data: it collects and organises the training and simulation evidence your own auditor asks for. It is not a statement about our certification status. A vendor that produces ISO 27001 evidence for you is not thereby ISO 27001 certified itself, and we will not let the same seven words quietly do both jobs.
We do not currently run a paid bounty programme. Reports are still welcome, still triaged within two business days, and still credited if you want the credit.
Questions
What researchers ask before they send the first email.