Early Access - WireGuard configs - No traffic or DNS query logs stored on VPN servers
Security

Security / Vulnerability Disclosure Policy

This policy gives people a safe channel to report security issues and describes the rules for responsible testing.

Effective: 21/08/2026Updated: 21/08/2026Version: 2026-08-21-r6

Where to Report

Send security reports to [email protected] with the subject Security Report - NoLogVPN.

Recommended Scope

the public NoLogVPN website
the account dashboard and authentication flows
the public API used by the application
device provisioning and WireGuard configuration flows

Responsible Testing Rules

do not access, modify, delete, or expose other users' data
do not disrupt the service or run volume, spam, or denial-of-service testing
do not attempt social engineering, phishing, physical attacks, or attacks against third-party providers
stop testing and report immediately if you encounter sensitive data
do not publish vulnerability details until NoLogVPN has reasonable time to fix the issue

What to Include

a description of the vulnerability and likely impact
reproduction steps, URLs, and the test account used
redacted screenshots or logs without secrets or other users' data
your contact details for clarification questions

Good-Faith Safe Harbor

If research is conducted in good faith, follows this policy, avoids harm, and is reported promptly, NoLogVPN will not initiate legal action solely for accidental and proportionate testing covered by these rules. This does not authorize breaking the law, intentionally accessing others' data, extortion, persistence in systems, or refusing a request to stop testing.

Response and Coordinated Disclosure

Our target is to acknowledge receipt within 5 business days and provide an initial status within 15 business days. Complexity may require more time, and these targets do not guarantee a fixed remediation deadline. We will try to coordinate the timing and content of public disclosure. For sensitive material, first send only a summary without secrets and ask us to arrange a safer channel.

Limits

NoLogVPN does not currently operate a public bug bounty program. Responsible reporting does not authorize access to data that is not yours, service disruption, or violation of applicable law.