Skip to content
Noroxi

Responsible disclosure policy

Even a security company can have vulnerabilities. If you find one, tell us first: we’ll respond quickly, fix it and credit your work.

Last updated Version 1.0Draft, awaiting legal review

This translation is provided for convenience; the Turkish version prevails.

Found a vulnerability?

Send your report encrypted with PGP. A human will reply within two business days.

PGP · 4F2A 9C1E 77B3 0D5A 2B61 E0C4 9A8D 13F7 5C2E 04B9

On this page
  1. 01How to report
  2. 02Scope
  3. 03Testing rules
  4. 04Safe harbor
  5. 05Process and timelines
  6. 06Acknowledgments
  7. 07Vulnerabilities we find
  8. 08security.txt

How to report

Send your report to guvenlik@noroxi.com. If it contains sensitive details, encrypt it with our PGP key, which has the fingerprint shown above. Please include:

  • the affected address, endpoint or component;
  • the type of vulnerability and its potential impact;
  • steps to reproduce, so we can verify it, and screenshots if available;
  • how we can reach you, and the name you would like to be credited under in the acknowledgments list.

You can write in Turkish or English. We also accept anonymous reports, but in that case we may not be able to get back to you.

Scope

In scope

  • noroxi.com and all its subdomains
  • The client report portal
  • The forms, CVE tracking and assistant on this site

Out of scope

  • Denial of service (DoS/DDoS) and load testing;
  • Social engineering and phishing targeting our employees, and physical access attempts;
  • Third-party services we use (report these directly to the company concerned);
  • Automated scanner output without a demonstrated exploitable impact;
  • Findings with no impact on their own: missing security headers, SPF/DMARC configuration, clickjacking on pages without sensitive actions, and missing rate limiting on forms that do not require a session.

If you’re not sure, ask before testing; we’ll clarify the scope together.

Testing rules

We expect you to follow the same rules we follow in our client engagements:

  • Do only the minimum needed to demonstrate the vulnerability; if you access personal data, stop and report it to us.
  • Do not access anyone else’s account or data; use your own accounts for testing.
  • Do not delete or modify data, and do not leave persistent access in any system.
  • Avoid tests that could disrupt or slow down the service.
  • Do not share the finding with anyone until the vulnerability is fixed.
  • Do not demand payment or set any other condition in exchange for the finding.

Safe harbor

We consider research carried out in good faith and in compliance with this policy to be authorized. We will not initiate legal proceedings or file a complaint against you because of such research. If a third party takes action against you, we will state clearly that you complied with this policy.

If you realize that you have accidentally gone beyond one of the rules, stop and write to us immediately. We act in good faith toward researchers who communicate openly.

Process and timelines

  1. 01
    First response2 business days

    We confirm that we have received your report and tell you who is handling it.

  2. 02
    Validation5 business days

    We verify the vulnerability, rate its severity with CVSS and share the result with you.

  3. 03
    Fix7–90 days

    Critical: 7 days. High: 30 days. Medium and low: 90 days. If we run late, we tell you why.

  4. 04
    ClosureAfter the fix

    We let you know so you can verify the fix; if you wish, we publish together.

Throughout the process, you receive a status update at least every two weeks; we don’t go silent.

Acknowledgments

We do not currently have a paid bug bounty program; if we launch one, we will announce it here. For every validated report, with your consent we add your name to the list below and, if you wish, write you a letter of thanks.

The list is empty for now.

It will open with the first validated report.

Vulnerabilities we find

When we find a vulnerability in a third-party product during our research or client tests, we follow coordinated disclosure.

NotificationWe notify the vendor through a secure channel, with technical details. If the vulnerability was found during a client test, we first obtain the client’s approval.After validation
DeadlineWe give the vendor 90 days to fix it. If the vulnerability is being actively exploited in the wild, this drops to 7 days.90 days
ExtensionIf the vendor is working on a fix and stays in contact, we extend the deadline within reason.If needed
PublicationAfter the patch is released, we publish a CVE record and a Turkish-language analysis.After the patch
No responseIf we fail to reach the vendor after 3 attempts, we request coordination through USOM or CERT/CC.30 days

Our publications never include working exploit code or step-by-step attack instructions; we focus on detection and remediation. For details, see our CVE publication principles. If you would like to contribute to a CVE analysis, use the contribution form.

security.txt

Our contact details are also published in the /.well-known/security.txt file, following the RFC 9116 standard, so automated tools can find us there.

/.well-known/security.txttext
Contact: mailto:guvenlik@noroxi.comExpires: 2027-09-27T00:00:00.000ZPolicy: https://noroxi.com/responsible-disclosureAcknowledgments: https://noroxi.com/responsible-disclosure#thanksPreferred-Languages: tr, enCanonical: https://noroxi.com/.well-known/security.txt

Send a report

The template comes with the headings we need.

Open email with template

Email

guvenlik@noroxi.com

PGP fingerprint

9A8D 13F7 5C2E 04B9

2 business days
first response
2 weeks
updates
7 days
critical fix