Menu
Report security issues responsibly.
Nodra treats vulnerabilities in tenant isolation, authorization, credentials, evidence integrity, identity, containment and recovery as high-priority security issues.
How to report
Send security reports privately to security@nodrasecurity.com. Do not publish sensitive vulnerability details in a public issue.
What to include
A useful report includes the affected version or commit, component or endpoint, reproduction steps, expected and actual behavior, security impact, and a proof-of-concept using non-sensitive test data.
High-priority examples
Examples include workspace/tenant isolation bypass, unauthorized protected-action execution, credential disclosure, approval or replay bypass, evidence-chain tampering, privilege escalation, or remote code execution in production paths.
Safe testing
Test only systems and data you own or are explicitly authorized to assess. Do not perform denial-of-service, destructive testing, social engineering, credential harvesting, or access another customer's information.
Coordinated disclosure
Nodra asks researchers to coordinate disclosure timing so remediation can be prepared and affected users can be protected. A security report is not treated as an authorization to exceed the scope of safe testing.
Independent assessments
Nodra distinguishes internal automated assurance from independent external testing. Independent penetration-test claims are published only when corresponding external evidence exists.