Security and responsible disclosure
Keeping customer data, credentials, and browser sessions safe is core to Notte. If you believe you have found a security vulnerability, please report it to us. For our compliance posture, see the Trust Center.
How to report
Email security@notte.cc. Please include a description of the issue, the affected endpoint or component, step-by-step reproduction instructions, and the potential impact. Do not include real customer data in your report.
What to expect
- We acknowledge reports within 3 business days.
- We keep you informed while we investigate and fix the issue.
- With your permission, we credit you once the issue is resolved.
Scope
In scope: notte.cc, console.notte.cc, api.notte.cc, and our open-source SDKs and CLI. Test only against accounts and resources you own.
Out of scope:
- Denial of service, load testing, or spam
- Social engineering or phishing of Notte staff or customers
- Physical attacks against offices or data centers
- Vulnerabilities in third-party services we do not control
- Findings from automated scanners without a demonstrated impact, missing security headers, or best-practice recommendations without an exploit
Rules of engagement
- Do not access, modify, or delete data that does not belong to you. If you encounter someone else's data, stop and report it.
- Do not degrade the service for other users.
- Give us reasonable time to fix the issue before disclosing it publicly, and coordinate the disclosure with us.
Safe harbor
We will not pursue legal action against researchers who act in good faith and follow this policy.
Rewards
Notte does not currently run a paid bug bounty program. Reporting under this policy does not require, and is not conditional on, any payment.