Trust

Security

Last updated

Keeping systems safe is what we do, and we're grateful to anyone who helps us do it better. If you think you've found a vulnerability in Noctys, please tell us. We'll listen, respond quickly, and work with you in good faith.

Reporting a vulnerability

Email your report to:

security@noctys.com

To help us act quickly, please include:

  • the affected URL, system, or component;
  • a description of the issue and its potential impact;
  • step-by-step instructions or a proof of concept that lets us reproduce it;
  • how you'd like to be credited, if at all.

This policy is also published in machine-readable form at /.well-known/security.txt.

What to expect

  • We'll acknowledge your report within three business days.
  • We'll confirm whether we can reproduce the issue and keep you informed as we fix it.
  • We'll tell you when it's resolved and, with your permission, credit you for the discovery.

We don't currently run a paid bug bounty program.

Scope

In scope: www.noctys.com and noctys.com, including the status dashboard and its API.

Out of scope:

  • systems we operate for our clients: those belong to our clients and are not open to testing. If you find something that affects a Noctys client, report it to us and we'll coordinate with them;
  • third-party services, including Microsoft 365. Report those to the vendor;
  • denial-of-service or load testing, social engineering, phishing, and physical attacks;
  • reports from automated scanners without a demonstrated impact, and missing “best practice” settings that pose no practical risk.

Safe harbour

If you research and report in good faith under this policy, we won't pursue legal action against you or ask law enforcement to investigate you. We consider that research authorized. Good faith means that you:

  • stay in scope and stop testing once you've confirmed a vulnerability;
  • don't access, change, or delete data that isn't yours, and don't retain any you come across;
  • don't degrade the service for anyone else;
  • give us reasonable time to fix the issue before you disclose it publicly. We suggest 90 days, and we're happy to coordinate a disclosure date with you.

If you're unsure whether something is allowed, ask us first at security@noctys.com.

How this site is protected

We practise on our own site what we do for our clients:

  • Encrypted by default. Every connection uses HTTPS, and HSTS tells browsers never to connect any other way.
  • No third parties. Fonts, scripts, and images come from our own server. There are no trackers, analytics, or advertising.
  • Strict content security policy. Browsers run only the code we publish and refuse to let the site be framed by others.
  • Minimal surface. The site collects no input from visitors. Its only API is read-only and rate-limited, and our Microsoft credentials never leave the server.
  • Minimal data. We keep only short-lived server logs. See our privacy policy.
Noctys services: Online Microsoft 365: Checking…