Security / Vulnerability Disclosure Policy
This policy gives people a safe channel to report security issues and describes the rules for responsible testing.
Where to Report
Send security reports to [email protected] with the subject Security Report - NoLogVPN.
Recommended Scope
Responsible Testing Rules
What to Include
Good-Faith Safe Harbor
If research is conducted in good faith, follows this policy, avoids harm, and is reported promptly, NoLogVPN will not initiate legal action solely for accidental and proportionate testing covered by these rules. This does not authorize breaking the law, intentionally accessing others' data, extortion, persistence in systems, or refusing a request to stop testing.
Response and Coordinated Disclosure
Our target is to acknowledge receipt within 5 business days and provide an initial status within 15 business days. Complexity may require more time, and these targets do not guarantee a fixed remediation deadline. We will try to coordinate the timing and content of public disclosure. For sensitive material, first send only a summary without secrets and ask us to arrange a safer channel.
Limits
NoLogVPN does not currently operate a public bug bounty program. Responsible reporting does not authorize access to data that is not yours, service disruption, or violation of applicable law.