Skip to main content

Vulnerability disclosure

Report suspected vulnerabilities to security@noblecloak.com. Machine-readable contact details: /.well-known/security.txt (RFC 9116).

What to expect

  • Acknowledgement within 3 business days.
  • An initial assessment and a remediation plan within 10 business days.
  • Credit in any resulting advisory, if you want it.

Safe harbour

We will not pursue legal action for good-faith research that respects the scope below, avoids privacy violations and service degradation, and gives us reasonable time to remediate before public disclosure.

In scope

*.noblecloak.com and the NobleCloak platform APIs.

Out of scope

Denial of service, social engineering, physical attacks, findings from automated scanners without a demonstrated impact, and reports against our subprocessors' own infrastructure — report those to the subprocessor.

We do not currently operate a paid bug bounty.

Last updated: 2026-07-27