Scope
In scope Reports are in scope only when they affect current, production Nova-owned assets and demonstrate a concrete security impact.
Testing must use only accounts, wallets, devices, API requests, data, and funds that you own or are explicitly authorized to use.
Out of scope
The following are out of scope and are not eligible for rewards:
Prohibited Conduct
The following activity is not authorized by this policy and may disqualify a report:- Phishing, social engineering, vishing, smishing, impersonation, or attempts to trick Nova users, employees, contractors, partners, or support channels.
- Sending live phishing links, malware, credential-harvesting pages, malicious attachments, or links that could harm Nova users or staff. Use screenshots, inert text, sanitized domains, or a safe proof of concept instead.
- Denial of service, DDoS, stress testing, destructive testing, spam, mass account creation, bulk automation, credential stuffing, brute force attacks, or rate-limit abuse.
- Accessing, copying, storing, modifying, deleting, transferring, freezing, signing with, or attempting to control funds, wallets, devices, accounts, credentials, tokens, logs, or data that you do not own.
- Attempting to obtain, use, or submit seed phrases, private keys, recovery phrases, passcodes, backup codes, signing payloads, session tokens, API credentials, or other secrets.
- Persistence, lateral movement, privilege escalation beyond what is necessary to demonstrate the issue, data exfiltration, extortion, threats, harassment, or unlawful conduct.
- Testing against third-party services, infrastructure, apps, networks, providers, or people without their explicit written authorization.
Submission Process
All vulnerability reports must be submitted through the official form. We do not accept vulnerability reports through social media, public GitHub issues, support chats, app reviews, or unofficial channels. Security Submission Form https://tally.so/r/dWEX0A Include:- Affected Nova-owned asset, URL, endpoint, app version, and device or OS version when relevant.
- Clear reproduction steps and expected versus observed behavior.
- A proof of concept that is safe, minimal, and non-destructive.
- The security boundary bypassed and the real-world user or Nova impact.
- Relevant timestamps, request IDs, transaction signatures, public wallet addresses, screenshots, logs, or videos where useful.
- Confirmation that you used only your own accounts, wallets, devices, data, and funds.
Rewards
Nova may offer monetary rewards for valid reports at Nova’s sole discretion. To be eligible for consideration, a report must:- Be the first complete and actionable report Nova receives for the issue.
- Demonstrate an exploitable security vulnerability with real-world impact to Nova users or Nova-owned production systems.
- Affect an in-scope, current production Nova asset.
- Include reliable reproduction steps and a safe proof of concept.
- Be reported privately through the official submission form.
- Comply with this policy from discovery through disclosure.
- Not guaranteed.
- Severity-based and determined solely by Nova.
- Paid only after validation and, when needed, remediation.
- Not paid for duplicates, known issues, public disclosures before authorization, out-of-scope findings, prohibited conduct, or reports that only describe abuse of open public APIs.
- Subject to sanctions, tax, payment, identity, and legal restrictions where applicable.
Disclosure Rules
Do not publicly disclose, discuss, sell, transfer, or share vulnerability details before Nova confirms that a fix has been deployed or explicitly authorizes disclosure in writing. For user protection, Nova may not publicly confirm, discuss, or disclose security issues until investigation is complete and any necessary updates are generally available. Public disclosure before authorization, repeated reopening of final decisions, harassment, threats, spam, or attempts to pressure Nova may disqualify a report and end participation in this program.Legal Safe Harbor
Nova supports good-faith security research that follows this policy. If you:- Act in good faith,
- Stay within the scope and conduct limits above,
- Avoid privacy violations, service disruption, data exfiltration, social engineering, phishing, and harm to users,
- Stop testing and report promptly if you encounter non-public data or unexpected access, and
- Report the issue privately through the official submission form,
- Activity outside this policy,
- Activity against third-party systems, people, infrastructure, providers, or assets,
- Unlawful conduct,
- Intentional harm,
- Phishing or social engineering,
- Public disclosure before authorization,
- Extortion, threats, harassment, or coercion,
- Accessing, copying, retaining, sharing, altering, or destroying data that is not yours, or
- Attempts to move, access, freeze, sign with, or control funds or wallets that are not yours.