Responsible disclosure

Responsible disclosure

Last updated 26 August 2026.

Report a security issue

Email hello@noustiq.com with enough detail to reproduce the issue. Machine-readable contact details are published at /.well-known/security.txt.

What you can expect from us

  • We will acknowledge your report and tell you whether we can reproduce it.
  • We will keep you informed while we work on a fix.
  • We will credit you if you want to be credited, and stay quiet if you do not.
  • We will not pursue legal action against anyone reporting in good faith.

What we ask from researchers

  • Give us reasonable time to fix the issue before disclosing publicly.
  • Do not access, modify or delete data that is not yours.
  • Do not run automated scanning that degrades the service for others.
  • Do not use social engineering, phishing or physical attacks against staff.

Scope

This website and the Noustiq application are in scope. Third-party services we use are not; report those to the relevant vendor.

We do not currently operate a paid bug bounty. That is a statement of fact rather than a reflection of how seriously a report is taken.