Responsible disclosure policy
Even a security company can have vulnerabilities. If you find one, tell us first: we’ll respond quickly, fix it and credit your work.
Last updated Version 1.0Draft, awaiting legal review
This translation is provided for convenience; the Turkish version prevails.
Found a vulnerability?
Send your report encrypted with PGP. A human will reply within two business days.
PGP · 4F2A 9C1E 77B3 0D5A 2B61 E0C4 9A8D 13F7 5C2E 04B9
On this page
How to report
Send your report to guvenlik@noroxi.com. If it contains sensitive details, encrypt it with our PGP key, which has the fingerprint shown above. Please include:
- the affected address, endpoint or component;
- the type of vulnerability and its potential impact;
- steps to reproduce, so we can verify it, and screenshots if available;
- how we can reach you, and the name you would like to be credited under in the acknowledgments list.
You can write in Turkish or English. We also accept anonymous reports, but in that case we may not be able to get back to you.
Scope
In scope
- noroxi.com and all its subdomains
- The client report portal
- The forms, CVE tracking and assistant on this site
Out of scope
- Denial of service (DoS/DDoS) and load testing;
- Social engineering and phishing targeting our employees, and physical access attempts;
- Third-party services we use (report these directly to the company concerned);
- Automated scanner output without a demonstrated exploitable impact;
- Findings with no impact on their own: missing security headers, SPF/DMARC configuration, clickjacking on pages without sensitive actions, and missing rate limiting on forms that do not require a session.
If you’re not sure, ask before testing; we’ll clarify the scope together.
Testing rules
We expect you to follow the same rules we follow in our client engagements:
- Do only the minimum needed to demonstrate the vulnerability; if you access personal data, stop and report it to us.
- Do not access anyone else’s account or data; use your own accounts for testing.
- Do not delete or modify data, and do not leave persistent access in any system.
- Avoid tests that could disrupt or slow down the service.
- Do not share the finding with anyone until the vulnerability is fixed.
- Do not demand payment or set any other condition in exchange for the finding.
Safe harbor
We consider research carried out in good faith and in compliance with this policy to be authorized. We will not initiate legal proceedings or file a complaint against you because of such research. If a third party takes action against you, we will state clearly that you complied with this policy.
If you realize that you have accidentally gone beyond one of the rules, stop and write to us immediately. We act in good faith toward researchers who communicate openly.
Process and timelines
- 01First response2 business days
We confirm that we have received your report and tell you who is handling it.
- 02Validation5 business days
We verify the vulnerability, rate its severity with CVSS and share the result with you.
- 03Fix7–90 days
Critical: 7 days. High: 30 days. Medium and low: 90 days. If we run late, we tell you why.
- 04ClosureAfter the fix
We let you know so you can verify the fix; if you wish, we publish together.
Throughout the process, you receive a status update at least every two weeks; we don’t go silent.
Acknowledgments
We do not currently have a paid bug bounty program; if we launch one, we will announce it here. For every validated report, with your consent we add your name to the list below and, if you wish, write you a letter of thanks.
The list is empty for now.
It will open with the first validated report.
Vulnerabilities we find
When we find a vulnerability in a third-party product during our research or client tests, we follow coordinated disclosure.
Our publications never include working exploit code or step-by-step attack instructions; we focus on detection and remediation. For details, see our CVE publication principles. If you would like to contribute to a CVE analysis, use the contribution form.
security.txt
Our contact details are also published in the /.well-known/security.txt file, following the RFC 9116 standard, so automated tools can find us there.
Contact: mailto:guvenlik@noroxi.comExpires: 2027-09-27T00:00:00.000ZPolicy: https://noroxi.com/responsible-disclosureAcknowledgments: https://noroxi.com/responsible-disclosure#thanksPreferred-Languages: tr, enCanonical: https://noroxi.com/.well-known/security.txtSend a report
The template comes with the headings we need.
Open email with templateguvenlik@noroxi.com
PGP fingerprint
9A8D 13F7 5C2E 04B9
- 2 business days
- first response
- 2 weeks
- updates
- 7 days
- critical fix