Nodra
Menu
SECURITY

Report security issues responsibly.

Nodra treats vulnerabilities in tenant isolation, authorization, credentials, evidence integrity, identity, containment and recovery as high-priority security issues.

How to report

Send security reports privately to security@nodrasecurity.com. Do not publish sensitive vulnerability details in a public issue.

What to include

A useful report includes the affected version or commit, component or endpoint, reproduction steps, expected and actual behavior, security impact, and a proof-of-concept using non-sensitive test data.

High-priority examples

Examples include workspace/tenant isolation bypass, unauthorized protected-action execution, credential disclosure, approval or replay bypass, evidence-chain tampering, privilege escalation, or remote code execution in production paths.

Safe testing

Test only systems and data you own or are explicitly authorized to assess. Do not perform denial-of-service, destructive testing, social engineering, credential harvesting, or access another customer's information.

Coordinated disclosure

Nodra asks researchers to coordinate disclosure timing so remediation can be prepared and affected users can be protected. A security report is not treated as an authorization to exceed the scope of safe testing.

Independent assessments

Nodra distinguishes internal automated assurance from independent external testing. Independent penetration-test claims are published only when corresponding external evidence exists.