Legal
Security Disclosure Policy
How to report a vulnerability in nox.markets: scope, safe harbor, timelines, what is out of scope, and the launch position that a paid bounty is not offered yet.
Last updated: 16 September 2026
Operator: NOX AETERNA GROUP LLC, a Wyoming limited liability company, trading as nox.markets, 5830 E 2nd St, Ste 7000 #34506, Casper, WY 82609, USA
Contact: security@nox.markets
Policy URL: https://nox.markets/security#responsible-disclosure
security.txt: https://nox.markets/.well-known/security.txt
Preferred language: English
This Security Disclosure Policy describes coordinated vulnerability reporting for nox.markets. It is the policy referenced by /.well-known/security.txt.
1. Coordinated disclosure (launch)
We operate coordinated disclosure. A paid bug bounty is not offered at launch. A paid program is Planned for 2027-06-30, after the first external penetration test (first test Planned 2026-12-15). We will not pay a ransom.
We acknowledge reports within 3 business days (US Eastern business calendar).
2. Safe harbor
If you research in good faith, do not exfiltrate data beyond the minimum needed for a proof of concept, do not degrade the Service, and report privately first to security@nox.markets, we will not bring a legal threat against that research under the computer-crime or similar laws we can control as NOX AETERNA GROUP LLC.
This safe harbor does not authorize:
- Access to other tenants’ data beyond one record to prove isolation is broken — then stop
- Exploits against our staff, phishing, or social engineering of staff or customers
- Physical attacks, or requiring us to decrypt
run_payloadyou exfiltrated - Public disclosure before we have had a reasonable chance to fix, unless we agree a date in writing
- Violation of third-party terms (connected SaaS, model providers)
3. In scope
*.nox.marketsproduction- The API
- Authentication and session handling
- IDOR / tenant isolation failures
- Secret leakage
- Remote code execution
- Stored XSS on app routes
4. Out of scope
- Marketing-site CMS XSS with no auth impact
- SPF/DKIM nitpicks without a working spoof
- Automated scanner dumps with no proof of concept
- Social engineering of staff or customers
- Physical security
- Denial of service (volumetric or application DoS)
- Issues in Customer’s own IdP, QuickBooks, HubSpot, or other connected systems
- Model hallucinations or product-quality errors (file those as product bugs, not as data breaches)
- Missing best-practice headers that do not yield a working exploit
5. How to report
Email security@nox.markets with:
- Affected URL or API
- Description and impact
- Step-by-step reproduction without a weaponized exploit against other tenants
- Proof of concept limited to your own workspace plus at most one extra record if proving isolation failure
- Your contact details
Encrypt if you can:
Do not file Customer Content from another tenant in a public GitHub issue.
6. Our response
- Acknowledge within 3 business days.
- Triage severity.
- Aim to fix in line with vulnerability SLAs on
/security:
- Critical (actively exploited or CVSS ≥ 9 and reachable): 24 hours
- High: 7 days
- Medium: 30 days
- Low: 90 days
- We may ask for a delay of public disclosure until a fix is deployed. We will not unreasonably delay.
- We may mention researchers in release notes only with their consent. We do not promise payment, swag, or a CVE assignment.
Penetration-test letters of attestation may be public when a test exists; full reports are under NDA on Scale+. We do not publish a pentest PDF on a marketing page. First independent web/API test: Planned 2026-12-15.
7. security.txt (contents we intend to serve)
Contact: mailto:security@nox.markets
Expires: 2027-09-15T00:00:00.00Z
Preferred-Languages: en
Canonical: https://nox.markets/.well-known/security.txt
Policy: https://nox.markets/security#responsible-disclosure
Hiring: https://nox.markets/careersRotate Expires at least annually.
8. Legal
This policy does not modify the Terms except as a public invitation to report in the manner described. Reports may contain personal data; we process them as security correspondence under the Privacy Policy.
Governing law: the laws of the State of Wyoming, USA.
