Legal

Vulnerability Reporting Policy

This Vulnerability Reporting Policy ("Policy") explains how security researchers and other individuals may report potential security vulnerabilities to Novapro Lab LLC ("Novapro Lab," "we," "us," or "our") in a responsible manner. We appreciate good-faith efforts to help us maintain the security of our systems.

1.Security Commitment

Novapro Lab takes reasonable steps to protect the confidentiality, integrity, and availability of systems we develop, operate, or maintain. Responsible reporting helps us identify and address issues that could affect our website, services, or users.

Effective date: June 20, 2026

2.Scope

This Policy applies to good-faith research involving:

  • The Novapro Lab public website
  • Novapro Lab-owned web applications, SaaS products, APIs, or systems when expressly made available for testing or covered by written permission

This Policy does not authorize testing of third-party systems, client systems, customer environments, hosting providers, payment processors, vendors, or other services unless Novapro Lab has expressly authorized such testing in writing.

3.Rules of Engagement

When conducting authorized security research, you agree to:

  • Use only test or demo accounts when available
  • Not access, modify, destroy, copy, or exfiltrate data that is not yours
  • Not perform denial-of-service attacks, brute force attacks, spam, phishing, social engineering, physical attacks, malware deployment, persistence mechanisms, credential attacks, or attacks against employees, contractors, or vendors
  • Not attempt to bypass rate limits or controls in a way that degrades service for others
  • Not publicly disclose unresolved vulnerabilities without our coordination
  • Comply with applicable laws and regulations

4.How to Report

Report potential vulnerabilities through our contact page or by email using the contact information below. Include enough detail for us to understand and reproduce the issue.

Please mention "Security Vulnerability Report" in your subject line or message so we can route your report appropriately.

5.What to Include

A helpful report generally includes:

  • Affected URL, product, or system
  • Clear reproduction steps
  • Potential impact and severity assessment
  • Supporting evidence such as screenshots, logs, or proof-of-concept details where appropriate
  • Test account used, if applicable
  • Your contact information

6.Our Commitment

Novapro Lab will use reasonable efforts to:

  • Acknowledge reports when feasible
  • Review and triage submissions in good faith
  • Request additional information when needed
  • Coordinate remediation where appropriate
  • Provide public credit only with the reporter's permission

7.Limited Safe Harbor

If you conduct security research in good faith, comply with this Policy, avoid privacy violations and service disruption, and report findings promptly to Novapro Lab before public disclosure, we will not pursue legal action against you solely for authorized activities that meet these conditions.

This safe harbor is limited, does not grant broad immunity, and does not apply to conduct outside this Policy or applicable law. Novapro Lab does not operate a bug bounty program and does not guarantee compensation, rewards, or payment for vulnerability reports unless expressly agreed in writing.

8.Out of Scope

The following are generally out of scope unless expressly authorized:

  • Third-party platforms, client environments, and vendor systems
  • Physical security, social engineering, and spam campaigns
  • Issues requiring unlikely user interaction without meaningful impact
  • Missing security headers or best-practice recommendations without demonstrable exploitability
  • Reports based solely on automated scanner output without validation

9.Changes to This Policy

We may update this Policy from time to time. The updated version will be posted on this page with a revised effective date.

10.Contact Information

To report a security vulnerability, contact:

Novapro Lab LLC
2579 SW 81st Ter. Unit 2587
Miramar, FL 33025
United States
Phone: +1 (305) 332-9661contact@novaprolab.com