Skip to main content

Security reporting

Report suspected vulnerabilities safely.

Send a concise, reproducible report to the dedicated security channel. No bug-bounty, response-time, or resolution commitment is offered on this prelaunch page.

Before you send a report

  • Describe the affected release, environment, impact, and minimal reproduction.
  • Do not send credentials, secrets, personal data, repository contents, or production data unless specifically requested through an agreed secure channel.
  • Do not disrupt systems, access other people's data, or exceed what is necessary to demonstrate the issue.
security@novarraai.com

Review the trust boundary.

See what Verify checks, what it prevents, and what always remains a human responsibility.