Security · Policy · last updated 23 September 2026
Responsible disclosure policy
If you've found a security problem in something Norveth built or runs, thank you. This page says how to report it, what we promise in return, and the rules that keep your research safe for both of us.
What's in scope
- norveth.app and its subdomains.
- Websites, bots and automations that Norveth built and still operates or maintains for a client.
Found something in a client's site we built but no longer run? Report it to us anyway; we'll pass it to the owner and tell you who they are if they agree.
How to report
Email hello@norveth.app with the subject starting “Security report”. Please include:
- the affected URL or component,
- steps to reproduce, and what an attacker could do with it,
- how you'd like to be credited, if at all.
Machine-readable contact details are at /.well-known/security.txt.
What we promise
- A human reply within 48 hours.
- An assessment within 7 days, and updates until it's fixed.
- Public credit once it's fixed, if you want it.
- No legal action against good-faith research that follows the rules below. If someone else takes action over it, we'll say publicly that your research was authorised by this policy.
We don't run a paid bug bounty. We'd rather say that here than let you find out after the work.
Rules for researchers
- Access only the minimum data needed to show the problem. If you reach personal data, stop and report.
- Don't change or delete data, and don't keep copies after reporting.
- No denial-of-service, spam, phishing, social engineering or physical attempts.
- Give us 90 days to fix it before you publish, or less if we agree it's fixed sooner.
When we find vulnerabilities in other people's software
- In client work: findings belong to the client and go only to the contact they named. We never publish them without the client's written permission.
- In third-party software we run into (a library, a platform, a vendor): we report privately to the vendor, following their own policy or bug bounty rules where one exists, and otherwise a 90-day coordinated disclosure window.
- We test only what a client's written permission or a program's published scope covers. Nothing else.