SecurityReport it. We will answer.

If you have found a vulnerability in a NOUSEC surface, this page tells you where to send it, what we consider in scope, and what we promise in return. We sell human risk management, so the least we can do is be straightforward about our own.

[email protected] · First response within 2 business days · English and Turkish
Scope is a decision — four things we hold, four we never touchWHAT WE HOLDWHAT WE NEVER TOUCHWork email addressName and departmentSimulation outcomeTraining completionEndpoint agentEmployee device installBrowsing historyKeystrokesNothing is installed on an employee device.The right-hand column is a decision, not a gap.
Scope is a decision — four things we hold, four we never touchWHAT WE HOLDWork email addressName and departmentSimulation outcomeTraining completionWHAT WE NEVER TOUCHEndpoint agentEmployee device installBrowsing historyKeystrokesA decision, not a gap.

How to report

One address, read by a person. There is no form to fill in and no account to create.

Step 1
Include the affected URL or endpoint, the steps to reproduce, and what you observed. Screenshots or a short capture help. English and Turkish are both read.
Step 2
We acknowledge within 2 business days
A human reply telling you whether we reproduced it — not an automated receipt. If it needs longer to investigate, we say so instead of going quiet.
Step 3
We fix, then we tell you
You hear what changed and when it shipped. If you want the credit, we name you in the advisory. If you would rather stay anonymous, that is fine too.

The same contact is published in our security.txt, per RFC 9116.

Scope

Stated plainly, because a policy that leaves scope vague pushes the researcher into guessing — and a wrong guess is how good-faith research turns into an incident.

In scope
nousec.com
The marketing site and everything served from it, including the demo request endpoint.
In scope, with limits
login.nousec.com
The platform login and application surface, tested against an account you control. No automated scanning, no load or stress testing, and no attempt to reach another tenant’s or another person’s data. Within those limits, findings here are welcome and covered by the safe harbour below.
Out of scope
Third-party services we do not control
Findings in services NOUSEC uses but does not operate should go to that provider. If you are not sure who owns a surface, ask us and we will tell you.
Out of scope
Simulation infrastructure
The domains used to deliver phishing simulations to customer employees are deliberately built to look like attacker infrastructure. Reporting them as malicious is expected and is not a vulnerability.

Safe harbour

What you get from us if you act in good faith.

If you follow the scope above, act in good faith, avoid privacy violations and service disruption, and give us a reasonable opportunity to fix the issue before disclosing it publicly, then NOUSEC will not pursue or support legal action against you for your research.

If a third party brings action against you for research that stayed inside this policy, we will make it known that your work was authorised under it. If you want that commitment in writing before you start, ask and we will send it.

What we ask of you

Four rules, all of them about not turning a test into an incident.

Use your own account
Do not access, modify or exfiltrate data belonging to another person or another tenant. If you stumble into someone else’s data, stop and tell us.
Do not degrade the service
No load testing, no denial of service, no automated scanning against the platform login.
Do not social-engineer our people
Staff, contractors and customers are out of scope. Phishing our employees is not research here — it is the product we sell, and we will treat it as an attack.
Give us time before disclosing
Tell us first and let us ship a fix. We will not use that time to stall; we will use it to fix.

What we do not claim

NOUSEC has not completed a SOC 2 or ISO/IEC 27001 audit. We hold no certification against either standard, and nothing on this site should be read as a certification claim. We have not commissioned an independent penetration test. When those things change, this page will say so, with a date.

Elsewhere on this site you will read that NOUSEC maps evidence per tenant to seven frameworks — KVKK, ISO/IEC 27001, NIS2, BDDK, SOC 2, GDPR and ISO/IEC 27701. That sentence describes what the product does with your data: it collects and organises the training and simulation evidence your own auditor asks for. It is not a statement about our certification status. A vendor that produces ISO 27001 evidence for you is not thereby ISO 27001 certified itself, and we will not let the same seven words quietly do both jobs.

We do not currently run a paid bounty programme. Reports are still welcome, still triaged within two business days, and still credited if you want the credit.

Questions

What researchers ask before they send the first email.

How do I report a security vulnerability?

Email [email protected] with enough detail to reproduce the issue: the affected URL or endpoint, the steps you took, and what you observed. Reports in English and Turkish are both read. Please do not open a public issue or post the finding publicly before we have replied. Our security.txt carries the same contact.

How quickly will I get a response?

We acknowledge and triage every report within two business days. That first reply is a real human response telling you whether we have reproduced the issue, not an automated receipt. If a report needs longer investigation we will say so and keep you updated rather than going quiet.

Is login.nousec.com in scope?

Yes, with limits. You may test against an account you control. Automated scanning, load or stress testing, and any attempt to access or take over another person's account are out of scope. The login surface is the most sensitive part of a security company's estate, so we would rather define how it is tested than pretend it will not be.

Do you pay for vulnerability reports?

We do not currently run a paid bounty programme. We will credit you by name in our advisory if you would like the credit, and we will tell you honestly what we fixed and when.

Is NOUSEC SOC 2 or ISO/IEC 27001 certified?

No. NOUSEC has not completed a SOC 2 or ISO/IEC 27001 audit and holds no certification against either standard. The platform produces framework-mapped evidence for your audit; that is a product capability and it is not a statement about our own certification status.

Will you take legal action against good-faith researchers?

No. If you follow the scope and rules of engagement on this page, act in good faith, and give us a reasonable chance to fix the issue before disclosing it, we will not pursue or support legal action against you, and we will say so in writing if you ask.

Found something? Tell us.

[email protected] — a person reads it, and you get an answer within two business days.

Published per RFC 9116 · security.txt