Vulnerability Disclosure Policy
Last updated: 12 July 2026
NodeNarrative ("we", "us", or "our") welcomes reports from security researchers who discover vulnerabilities in our services. We value the work of the security community and will investigate every legitimate report we receive. This policy explains how to report a vulnerability to us, what is in scope, and what you can expect from us in return.
1. Reporting a vulnerability
Please email your report to security@nodenarrative.io. To help us triage and reproduce the issue quickly, include:
- A description of the vulnerability and its potential impact.
- Step-by-step instructions to reproduce the issue.
- The affected URLs, endpoints, or components.
- Any relevant proof-of-concept material (requests, screenshots, code).
We do not currently offer PGP-encrypted reporting. Please do not include sensitive personal data in your report beyond the minimum needed to demonstrate the issue.
2. Scope
This policy applies to web properties and APIs operated by NodeNarrative:
- nodenarrative.io and subdomains (*.nodenarrative.io)
- api.nodenarrative.io (platform API)
- app.nodenarrative.io (dashboard application)
- collector.nodenarrative.io (event collection)
Third-party services we integrate with but do not operate, such as Stripe, Google, Meta, and Shopify, are not in scope. Please report vulnerabilities in those platforms to the relevant vendor through their own disclosure programmes.
3. Safe harbour
We consider good-faith security research conducted in accordance with this policy to be authorised. Specifically:
- We will not pursue legal action against you, or report you to law enforcement, for accidental, good-faith violations of this policy.
- We consider research conducted under this policy to be authorised under applicable anti-hacking and anti-circumvention laws, and we waive any claims against you for circumventing the technology controls we use to protect the applications in scope.
- You are expected to comply with all applicable laws, including data-protection law. Do not access, modify, or destroy data that does not belong to you.
- If you encounter personal data (yours or anyone else's) during testing, stop immediately, do not retain or share it, and report it to us straight away.
If you are ever unsure whether your research is consistent with this policy, contact us at security@nodenarrative.io before proceeding.
4. Rules of engagement
To keep your research within the safe harbour above:
- No denial of service. Do not perform DoS, DDoS, or other volumetric or resource-exhaustion testing.
- No social engineering. Do not phish, pretext, or otherwise socially engineer our staff, contractors, or customers.
- No physical attacks against our people, property, or facilities.
- Only test against accounts you own. Do not attempt to access or affect other users' accounts or data.
- Keep automated scanning polite. Do not run automated tools at rates that could degrade service for other users.
5. Our commitment
When you report a vulnerability to us under this policy, we will:
- Acknowledge your report within 3 business days.
- Provide a status update within 10 business days, including our assessment and expected remediation timeline where possible.
- Keep you informed as we work on a fix, and notify you when it is resolved.
We practise coordinated disclosure: we ask that you give us 90 days from your initial report before disclosing the issue publicly, so we have a fair opportunity to remediate. We are happy to coordinate on timing and, with your permission, to credit you when the issue is resolved.
6. Out-of-scope examples
The following classes of report are generally not accepted unless accompanied by a demonstrated, exploitable impact:
- Clickjacking on pages with no sensitive actions.
- SPF, DKIM, or DMARC configuration observations without a working exploit.
- Missing security headers without demonstrated impact.
- Software version banners or other version disclosure on their own.
7. security.txt (RFC 9116)
In line with RFC 9116, our machine-readable security contact information is published at https://nodenarrative.io/.well-known/security.txt. This page is the Policy document that file refers to.