Skip to content

Legal

Security Disclosure Policy

How to report a vulnerability in nox.markets: scope, safe harbor, timelines, what is out of scope, and the launch position that a paid bounty is not offered yet.

Last updated: 16 September 2026
Operator: NOX AETERNA GROUP LLC, a Wyoming limited liability company, trading as nox.markets, 5830 E 2nd St, Ste 7000 #34506, Casper, WY 82609, USA
Contact: security@nox.markets
Policy URL: https://nox.markets/security#responsible-disclosure
security.txt: https://nox.markets/.well-known/security.txt
Preferred language: English

This Security Disclosure Policy describes coordinated vulnerability reporting for nox.markets. It is the policy referenced by /.well-known/security.txt.


1. Coordinated disclosure (launch)

We operate coordinated disclosure. A paid bug bounty is not offered at launch. A paid program is Planned for 2027-06-30, after the first external penetration test (first test Planned 2026-12-15). We will not pay a ransom.

We acknowledge reports within 3 business days (US Eastern business calendar).


2. Safe harbor

If you research in good faith, do not exfiltrate data beyond the minimum needed for a proof of concept, do not degrade the Service, and report privately first to security@nox.markets, we will not bring a legal threat against that research under the computer-crime or similar laws we can control as NOX AETERNA GROUP LLC.

This safe harbor does not authorize:

  • Access to other tenants’ data beyond one record to prove isolation is broken — then stop
  • Exploits against our staff, phishing, or social engineering of staff or customers
  • Physical attacks, or requiring us to decrypt run_payload you exfiltrated
  • Public disclosure before we have had a reasonable chance to fix, unless we agree a date in writing
  • Violation of third-party terms (connected SaaS, model providers)

3. In scope

  • *.nox.markets production
  • The API
  • Authentication and session handling
  • IDOR / tenant isolation failures
  • Secret leakage
  • Remote code execution
  • Stored XSS on app routes

4. Out of scope

  • Marketing-site CMS XSS with no auth impact
  • SPF/DKIM nitpicks without a working spoof
  • Automated scanner dumps with no proof of concept
  • Social engineering of staff or customers
  • Physical security
  • Denial of service (volumetric or application DoS)
  • Issues in Customer’s own IdP, QuickBooks, HubSpot, or other connected systems
  • Model hallucinations or product-quality errors (file those as product bugs, not as data breaches)
  • Missing best-practice headers that do not yield a working exploit

5. How to report

Email security@nox.markets with:

  • Affected URL or API
  • Description and impact
  • Step-by-step reproduction without a weaponized exploit against other tenants
  • Proof of concept limited to your own workspace plus at most one extra record if proving isolation failure
  • Your contact details

Encrypt if you can:

Do not file Customer Content from another tenant in a public GitHub issue.


6. Our response

  1. Acknowledge within 3 business days.
  2. Triage severity.
  3. Aim to fix in line with vulnerability SLAs on /security:
  • Critical (actively exploited or CVSS ≥ 9 and reachable): 24 hours
  • High: 7 days
  • Medium: 30 days
  • Low: 90 days
  1. We may ask for a delay of public disclosure until a fix is deployed. We will not unreasonably delay.
  2. We may mention researchers in release notes only with their consent. We do not promise payment, swag, or a CVE assignment.

Penetration-test letters of attestation may be public when a test exists; full reports are under NDA on Scale+. We do not publish a pentest PDF on a marketing page. First independent web/API test: Planned 2026-12-15.


7. security.txt (contents we intend to serve)

Contact: mailto:security@nox.markets
Expires: 2027-09-15T00:00:00.00Z
Preferred-Languages: en
Canonical: https://nox.markets/.well-known/security.txt
Policy: https://nox.markets/security#responsible-disclosure
Hiring: https://nox.markets/careers

Rotate Expires at least annually.


This policy does not modify the Terms except as a public invitation to report in the manner described. Reports may contain personal data; we process them as security correspondence under the Privacy Policy.

Governing law: the laws of the State of Wyoming, USA.