Responsible Disclosure Policy
Responsible Disclosure Policy
We're a security-first company, and we take vulnerability reports seriously. This policy explains how researchers can report issues to us, what's in scope, and what to expect in return.
Scope
The following are in scope for reports:
app.nodowntimeshield.comand any*.nodowntimeshield.comsubdomain- Our public REST API at
/api/external/v1/* - Our GitHub App and OAuth integrations
- Our Go agent, PHP agent, browser extension, VS Code extension, and pre-commit hook
- Our official mobile app (iOS / Android)
Out of scope (please do not test these):
- Automated denial-of-service / load tests
- Social engineering of our employees, contractors, or customers
- Physical access to our offices
- Findings on third-party platforms we use (report those upstream)
- Self-XSS or attacks requiring physical access to a victim's device
- Findings on customer-installed agents (those are the customer's responsibility)
Safe Harbour
We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid privacy violations and service disruption
- Only access data necessary to demonstrate the vulnerability
- Do not store, transfer, or otherwise process customer data
- Report the issue via the channel below before public disclosure
How to Report
Send your report to [email protected] — preferably encrypted
with our PGP key (linked in /.well-known/security.txt).
Include:
- A clear technical description of the vulnerability
- Steps to reproduce, ideally with a proof-of-concept
- The impact: what an attacker could do with this
- Your name and contact details (we'll credit you on the Hall of Fame unless you ask not to be listed)
What to Expect
| Step | Timeline | |-------------------------|---------------| | Acknowledgement | Within 48h | | Triage decision | Within 5 days | | Status update | Every 2 weeks | | Patch deployment | Severity-dependent (critical: ≤7 days, high: ≤30 days) | | Hall of Fame credit | After patch |
Hall of Fame
We publicly credit researchers who help us improve. See our running list at /security/hall-of-fame. If you'd prefer to remain anonymous, just let us know in your report.
Bug Bounty
We don't operate a paid bug bounty programme today, but we do send swag and LinkedIn recommendations for high-impact reports, and we will write a public case study (with credit) for any critical-severity finding that affects the platform itself.
We're evaluating moving to a paid programme via HackerOne / Bugcrowd in 2026 — follow @nodowntimeshield for updates.