Report a concern.
Keep the boundary clear.
A potential vulnerability deserves a clear reporting route. Testing permission, disclosure scope and handling commitments must be explicit.
Reporting contact
Security contact: security@novagrex.co.uk.
The address was supplied by the owner, but mailbox receipt and the responsible operator have not been verified. No acknowledgment time is promised.
Scope and permission
Approved NovaGrex assets and testing scope: {{DISCLOSURE_ASSETS_AND_AUTHORIZATION}}.
A public URL, a cybersecurity service page or this draft does not give permission to test a system. Do not infer authorization for NovaGrex systems, customer systems or third-party infrastructure. Obtain the necessary authorization before conducting activity that requires it.
Useful report information
A high-level initial report should identify the affected asset, the observed behavior, the potential impact and how to contact you. Include only the minimum evidence needed to explain the concern.
Do not send credentials, bulk personal data, customer records or live exploit material through the general inquiry form. A secure method for sharing sensitive evidence must be agreed with the responsible operator. No encryption key is published unless it has been verified.
Important boundaries
Do not disrupt service, access or modify other people's data, install persistence, carry out social engineering, or continue accessing information beyond what is authorized. If you encounter personal or confidential data, stop the activity and report the concern with minimal evidence.
This draft offers no bug bounty, financial reward, legal immunity or safe harbor. Any final authorization and safe-harbor wording needs explicit operator and qualified legal approval.
Handling and publication
Responsible operator, acknowledgment process and coordinated publication arrangements: {{DISCLOSURE_HANDLING_PROCESS}}.
A report is not a guarantee of a particular fix or timeline. Final commitments must match actual operational capacity. The production site will publish a standards-based security.txt only when its contact, canonical domain and expiry are valid and its renewal owner is assigned.
/.well-known/security.txt remains unavailable while required information is unresolved.