Vulnerability disclosure
Report suspected vulnerabilities to security@noblecloak.com. Machine-readable contact details: /.well-known/security.txt (RFC 9116).
What to expect
- Acknowledgement within 3 business days.
- An initial assessment and a remediation plan within 10 business days.
- Credit in any resulting advisory, if you want it.
Safe harbour
We will not pursue legal action for good-faith research that respects the scope below, avoids privacy violations and service degradation, and gives us reasonable time to remediate before public disclosure.
In scope
*.noblecloak.com and the NobleCloak platform APIs.
Out of scope
Denial of service, social engineering, physical attacks, findings from automated scanners without a demonstrated impact, and reports against our subprocessors' own infrastructure — report those to the subprocessor.
We do not currently operate a paid bug bounty.
Last updated: 2026-07-27