NOBLER WORKS - VULNERABILITY DISCLOSURE POLICY Last updated: 2026-08-16 REPORTING Email security@noblerworks.com with enough detail to reproduce: the affected URL or component, the steps you took, and what you observed. A proof of concept helps. If the issue is sensitive, say so and we will arrange an encrypted channel. RESPONSE TARGETS Acknowledgement within 3 business days Initial assessment within 10 business days Fix target Critical 7 days | High 30 days | Medium/Low next cycle Credit is offered by default. Tell us if you would rather remain anonymous. IN SCOPE - noblerworks.com and its subdomains (including ncc.noblerworks.com and personal-os.noblerworks.com) PRODUCT DOMAINS Our products publish their own disclosure channels on their own domains: - gitgood.dev -> security@gitgood.dev (bug bounty: https://gitgood.dev/bug-bounty) - semantix.chat -> security@semantix.chat Reports about a product sent to security@noblerworks.com will be routed. OUT OF SCOPE - Our customers' own deployments. nobler-os is installed into each customer's own cloud account and those installations belong to them. Report anything you find to us and we will coordinate with the customer. - Third-party services we consume (AWS, GCP, Stripe, GitHub) - report those to the provider directly. - Automated scanner output with no demonstrated impact. - Social engineering, physical attacks, and denial of service. SAFE HARBOUR We will not pursue legal action for good-faith research that stays in scope, avoids privacy violations, data destruction and service degradation, uses only accounts you own or are permitted to test, and allows reasonable time to remediate before public disclosure. If you are unsure whether something is in scope, ask first. OUR COMMITMENTS We will keep you updated on progress, tell you when the issue is resolved, and will not require an NDA as a condition of reporting.