Responsible disclosure

Help us investigate without putting people or data at risk.

NoBS Remote is prelaunch. If you believe you have found a security issue in the public website or a NoBS Remote component you were expressly authorized to test, begin with a minimal report.

Initial contact

Send only what is needed to triage.

Email pilot@nobsremote.com with the subject Security report — initial triage.

  • A short description of the issue and affected public URL or component.
  • The date observed and high-level reproduction conditions.
  • Potential impact, without including customer data, credentials, exploit payloads, or sensitive logs.
  • A way to contact you so a safer exchange can be arranged if needed.
Prelaunch channel

Do not email secrets or sensitive evidence.

The current mailbox is suitable for initial triage, not confidential exploit material. Wait for a confirmed secure channel before sending detailed proof, attachments, credentials, personal data, or unpublished code.

Research boundaries

Reduce harm while validating a concern.

Use only authorized targets

Limit testing to systems you own or have explicit permission to test. Third-party services, other users, and private infrastructure are out of scope.

Stop at the first proof

Do not access, copy, alter, retain, or disclose data that is not yours. Do not pursue persistence, lateral movement, or a broader exploit chain.

Avoid disruption

Do not use denial of service, spam, destructive tests, automated high-volume scanning, physical attacks, or social engineering.

No public bug-bounty program, reward commitment, or blanket testing authorization is offered at this stage. Written authorization must be obtained before testing anything beyond ordinary, low-impact observation of a public surface.

What happens next

We will review a good-faith report and respond when practical. Response timing, disclosure timing, remediation, credit, and any further validation will be coordinated case by case. Please do not publish an unresolved issue or identifying data without a mutually understood disclosure plan.

Emergency threats to life, safety, or an actively compromised third party should be reported to the appropriate service provider or authorities as well as to us.

Last reviewed: July 29, 2026.