Responsible disclosure.
We build a security product, so we hold our own surface to the same bar. If you find a weakness in Notra, we want to hear about it, and we won’t pursue researchers acting in good faith.
- TLS everywhere
- Encrypted at rest
- Ownership verification before scanning
- Non-destructive probes
- Audit-logged access
- Least-privilege data access
- Secrets never sold or shared
- Abuse contact in every scan UA
What we ask
Give us a clear proof of concept and enough detail to reproduce the issue. Test only against your own account or assets you control. Don’t run automated scanners against our production billing or auth flows, don’t access, modify, or exfiltrate other users’ data, and don’t degrade the service for anyone else.
What we promise
If you follow the above, we will not take legal action, we’ll keep you updated as we triage and fix, and we’ll credit you once the issue is resolved if you’d like the recognition. We don’t run a paid bounty yet, this is a good-faith safe harbour, and we’ll say so plainly rather than imply a reward that doesn’t exist.
Out of scope
Reports generated purely by automated tools with no demonstrated impact, missing best-practice headers on marketing pages, rate-limiting on non-sensitive endpoints, and social-engineering or physical attacks. When in doubt, send it anyway with your reasoning.
Live component health is on our status page, API and integration details are in the documentation, and handling of your data is described in our privacy notice. To report misuse of the scanner against a site you own, see abuse reporting.
Found something in our surface?
security@notra.audit reaches a founder. Good-faith research is welcome here.