Trust

Responsible Security Disclosure

Nolote appreciates good-faith security research that helps protect users, customers, products, and company systems.

This page explains how to report a potential vulnerability safely. It is a coordination policy, not authorization to access data, disrupt services, or test systems outside the defined scope.

Before reporting

Use the product-specific security contact when one is published. Otherwise, use the Nolote security reporting channel listed below.

Do not include passwords, private keys, access tokens, raw personal data, payment-card data, or a complete customer dataset in the initial message. A security team member can provide a protected exchange method when additional evidence is required.

Reporting channel

Use the verified security contact published in Nolote’s security.txt file:

https://www.nolote.com/.well-known/security.txt

What to include

A useful report contains:

  • A clear description of the potential issue
  • The affected Nolote or product domain, application, version, endpoint, or component
  • Safe steps to reproduce
  • The observed and expected behavior
  • Potential impact
  • Minimal redacted evidence
  • Whether any user or customer data was accessed
  • Your preferred contact method
  • Any disclosure deadline you are considering

Please send one issue per report when practical. Explain related chains clearly if multiple findings combine into one material impact.

Good-faith research expectations

Researchers should:

  • Make a reasonable effort to avoid privacy violations and data exposure
  • Use accounts and systems they own or are authorized to test
  • Stop after confirming the minimum evidence required
  • Avoid persistence, lateral movement, and privilege expansion beyond the issue
  • Avoid changing, deleting, or corrupting data
  • Avoid denial of service, load testing, resource exhaustion, and traffic amplification
  • Avoid phishing, social engineering, physical intrusion, and employee targeting
  • Avoid accessing another person’s private content
  • Keep the issue confidential while Nolote investigates and coordinates remediation
  • Comply with applicable law

If sensitive data is encountered unexpectedly, stop, do not copy more, and explain what was observed.

Out of scope without written authorization

  • Denial-of-service or volumetric testing
  • Automated scanning that creates material load
  • Credential stuffing, password spraying, or brute force
  • Social engineering or phishing
  • Physical security testing
  • Third-party services and infrastructure not controlled by Nolote
  • App-store, cloud-provider, payment-provider, messaging-provider, or open-source issues that do not result from Nolote’s implementation
  • Self-XSS or issues requiring a user to attack themselves without another meaningful impact
  • Missing security headers without a demonstrated risk
  • Version disclosure without exploitability
  • Spam, rate-limit, or abuse reports without a reproducible product impact
  • Product behavior explicitly documented as a limitation
  • Reports based solely on automated-tool output without validation

A listed exclusion does not mean Nolote is uninterested. It means the researcher should contact the team before conducting higher-risk testing.

Product scope

In scope

  • www.nolote.com
  • Approved Nolote-controlled API and corporate domains
  • Product domains specifically marked as participating
  • Official mobile applications and downloadable clients, by current store or package identifier

Product-managed separately

  • HushShield ThreatGate
  • LabelVPN
  • Rynelra
  • FiestaVPN
  • Prodara
  • ChangeMint
  • Rankroom
  • VibeGuard Bot

Do not assume every subdomain, customer-operated deployment, self-hosted installation, test environment, or third-party provider is in scope.

How Nolote handles reports

Nolote’s process is to:

  1. 01Acknowledge a complete report through the published channel.
  2. 02Triage scope, reproducibility, severity, and affected product.
  3. 03Request a secure exchange route when more evidence is needed.
  4. 04Coordinate investigation with the responsible product and platform owners.
  5. 05Develop, validate, and deploy an appropriate remediation.
  6. 06Communicate material status changes when possible.
  7. 07Coordinate disclosure timing based on user risk and remediation progress.
  8. 08Credit the researcher when requested, appropriate, and legally permitted.

Disclosure and public communication

Please give Nolote a reasonable opportunity to investigate and remediate before public disclosure.

Nolote may ask to delay publication when users remain at material risk or a coordinated dependency fix is still in progress. Researchers retain responsibility for their own legal obligations, and Nolote cannot guarantee a reward, credit, or specific timeline.

Rewards

Nolote does not currently publish a standing monetary bug-bounty program. Recognition or discretionary rewards, if any, are determined case by case and are not guaranteed.

Security notices

Material security updates are published through the affected product’s official status, support, release, or security channel. This disclosure page is not a live incident-status page.

Common questions

Can I test a customer-operated ThreatGate installation?

Not under Nolote’s corporate scope unless the customer and Nolote have provided written authorization. Self-hosted infrastructure may belong to the customer.

Can I run a DDoS test against Nolote or a product?

No. Denial-of-service, volumetric, amplification, and resource-exhaustion testing require explicit written coordination.

Should I send a proof-of-concept exploit?

Send the minimum safe reproduction first. The security team will request an approved transfer method when code or larger artifacts are necessary.

Will Nolote publicly credit me?

Credit may be provided with mutual agreement after remediation, subject to safety, legal, privacy, and duplicate considerations.

Is this a bug-bounty program?

Not unless an active reward program is separately published.

Next step

Help us protect the people who use our products