Last updated: July 23, 2026
Norveth is an independently operated platform. If you find a security issue, we'd genuinely rather hear it from you first.
We won't pursue legal action against security researchers who discover and report vulnerabilities in good faith, in accordance with this policy. Testing conducted consistent with this policy is authorized.
Email security@norveth.app with what you found and how to reproduce it.
norveth.app and its subdomainsnorveth.app/api)Norveth is currently a solo-operated project — you'll get a personal reply, not a ticketing queue, but that also means response times aren't governed by a formal SLA. Genuine, responsibly disclosed reports are prioritized and acknowledged as quickly as possible, and we're glad to credit you publicly once it's fixed, if you'd like. There's no paid bug bounty program today.