Responsible Disclosure Policy

Responsible Disclosure Policy

We're a security-first company, and we take vulnerability reports seriously. This policy explains how researchers can report issues to us, what's in scope, and what to expect in return.

Scope

The following are in scope for reports:

  • app.nodowntimeshield.com and any *.nodowntimeshield.com subdomain
  • Our public REST API at /api/external/v1/*
  • Our GitHub App and OAuth integrations
  • Our Go agent, PHP agent, browser extension, VS Code extension, and pre-commit hook
  • Our official mobile app (iOS / Android)

Out of scope (please do not test these):

  • Automated denial-of-service / load tests
  • Social engineering of our employees, contractors, or customers
  • Physical access to our offices
  • Findings on third-party platforms we use (report those upstream)
  • Self-XSS or attacks requiring physical access to a victim's device
  • Findings on customer-installed agents (those are the customer's responsibility)

Safe Harbour

We will not pursue legal action against researchers who:

  1. Make a good-faith effort to avoid privacy violations and service disruption
  2. Only access data necessary to demonstrate the vulnerability
  3. Do not store, transfer, or otherwise process customer data
  4. Report the issue via the channel below before public disclosure

How to Report

Send your report to [email protected] — preferably encrypted with our PGP key (linked in /.well-known/security.txt).

Include:

  • A clear technical description of the vulnerability
  • Steps to reproduce, ideally with a proof-of-concept
  • The impact: what an attacker could do with this
  • Your name and contact details (we'll credit you on the Hall of Fame unless you ask not to be listed)

What to Expect

| Step | Timeline | |-------------------------|---------------| | Acknowledgement | Within 48h | | Triage decision | Within 5 days | | Status update | Every 2 weeks | | Patch deployment | Severity-dependent (critical: ≤7 days, high: ≤30 days) | | Hall of Fame credit | After patch |

Hall of Fame

We publicly credit researchers who help us improve. See our running list at /security/hall-of-fame. If you'd prefer to remain anonymous, just let us know in your report.

Bug Bounty

We don't operate a paid bug bounty programme today, but we do send swag and LinkedIn recommendations for high-impact reports, and we will write a public case study (with credit) for any critical-severity finding that affects the platform itself.

We're evaluating moving to a paid programme via HackerOne / Bugcrowd in 2026 — follow @nodowntimeshield for updates.