Contents
- Article 1 - Purpose and commitment
- Article 2 - Scope
- Article 3 - Reporting procedures
- Article 4 - Commitments of the reporter
- Article 5 - Commitments of the Publisher
- Article 6 - Coordinated disclosure
- Article 7 - Confidentiality
- Article 8 - Excluded activities
- Article 9 - Reward
Evorax Technologies welcomes good-faith vulnerability reports made in the interest of protecting Users of the Noryo service (hereinafter the "Service"). This policy specifies the scope, the reporting procedures and the reciprocal commitments.
Article 1 - Purpose and commitment
The purpose of this policy is to provide a framework for the responsible disclosure of security vulnerabilities affecting the Service and to offer a clear framework to persons wishing to report them.
Article 2 - Scope
2.1 Covered
This concerns vulnerabilities affecting the websites, applications and interfaces of the Service operated by the Publisher.
2.2 Out of scope
This excludes in particular services and infrastructure operated by third parties, as well as vulnerabilities that are already known or have no real impact on security.
Article 3 - Reporting procedures
Any report is sent to legal@noryo.app and includes a clear description of the vulnerability, the steps to reproduce it, its potential impact and, as far as possible, a proof of concept.
Article 4 - Commitments of the reporter
- Act in good faith and refrain from any breach of the confidentiality, integrity or availability of third-party data.
- Limit any access to data that does not belong to them to the strict minimum necessary to demonstrate the vulnerability.
- Refrain from exploiting the vulnerability beyond what is necessary and from disclosing it publicly before it is fixed.
- Grant the Publisher a reasonable time to fix it.
Article 5 - Commitments of the Publisher
- Acknowledge receipt of the report and keep the reporter informed of its handling.
- Refrain from any action against a reporter who has acted in good faith and in compliance with this policy.
- Handle vulnerabilities with the appropriate priority and remediate confirmed flaws within reasonable timeframes.
Article 6 - Coordinated disclosure
The Publisher favours coordinated disclosure: any public communication relating to a vulnerability takes place after it has been fixed, in consultation with the reporter where possible.
Article 7 - Confidentiality
The information transmitted in connection with a report is treated confidentially and used solely for the purpose of handling the vulnerability.
Article 8 - Excluded activities
This excludes in particular tests resulting in a degradation of the Service, unauthorised access to the data of other Users, social engineering, denial-of-service attacks and attacks targeting third-party providers.
Article 9 - Reward
This policy does not establish a reward programme, unless expressly indicated otherwise by the Publisher.