> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nshield.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Vulnerability Disclosure

> Responsible vulnerability disclosure policy for Nova Wallet, Nova-owned public APIs, and Nova-owned documentation.

Nova welcomes responsible disclosure of security vulnerabilities that create a real, exploitable risk to Nova users or Nova-owned production systems.

Nova Wallet is a **non-custodial iOS wallet**. Nova does not custody user funds and does not have access to user seed phrases, private keys, passcodes, backup codes, recovery phrases, or signing authority. Do not submit secrets to Nova and do not attempt to access funds, accounts, wallets, devices, or data that you do not own.

This policy is a vulnerability disclosure program with optional, discretionary rewards. Submitting a report does not guarantee a reward, response, public credit, or continued participation in the program.

## Scope

**In scope**

Reports are in scope only when they affect current, production Nova-owned assets and demonstrate a concrete security impact.

| Asset                                           | In scope examples                                                                                                                                                                                                         |
| ----------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Nova Wallet for iOS                             | Vulnerabilities in the latest public App Store version that could compromise wallet integrity, transaction review, local authorization, local data protection, or user security.                                          |
| Nova-owned public APIs                          | Exploitable vulnerabilities in Nova-owned production API services, including documented public APIs, that bypass a real security boundary or expose non-public Nova data.                                                 |
| Nova-owned documentation and developer surfaces | Vulnerabilities in `docs.nshield.org` or other Nova-owned documentation surfaces that create a real user security risk, such as account compromise, stored cross-site scripting with impact, or unauthorized data access. |
| Official Nova-owned domains                     | Security issues on domains controlled by Nova, when the affected system is production and the impact is reproducible.                                                                                                     |

Testing must use only accounts, wallets, devices, API requests, data, and funds that you own or are explicitly authorized to use.

**Out of scope**

The following are out of scope and are not eligible for rewards:

| Category                                  | Examples                                                                                                                                                                                                                                                                                                                                  |
| ----------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Unsupported or unreleased features        | Reports about products, flows, assets, contracts, endpoints, or features that Nova does not currently publish as supported production surfaces.                                                                                                                                                                                           |
| Public API abuse                          | Nova public APIs are intentionally open. Calling open endpoints, scraping public-chain data, high-volume access, docs playground use, endpoint enumeration, missing API-key complaints, rate-limit complaints, quota exhaustion, or hypothetical abuse of public data is not a vulnerability without a concrete security boundary bypass. |
| Phishing and impersonation                | Phishing pages, fake apps, fake support accounts, scam tokens, malicious links, social engineering, impersonation, and brand abuse are not accepted as vulnerability reports. Do not send live phishing links to Nova.                                                                                                                    |
| Third-party systems                       | Apple, App Store, iOS, Solana, validators, RPC providers, cloud providers, wallet providers, bridges, exchanges, onramp providers, analytics providers, SDKs, and other non-Nova systems. Report those issues to the relevant third party.                                                                                                |
| User-controlled or public blockchain data | Public wallet activity, token metadata, public token mints, public transaction history, public market data, or third-party on-chain behavior unless a Nova-owned system creates a separate security issue.                                                                                                                                |
| UI, UX, content, and product feedback     | Visual issues, copy changes, broken links without security impact, missing features, support requests, product suggestions, and compliance opinions.                                                                                                                                                                                      |
| Low-impact web findings                   | Missing or non-ideal security headers, cookie flags without exploitability, clickjacking without sensitive action impact, version banners, SPF/DKIM/DMARC observations, TLS preference issues, or scanner-only findings without a working exploit.                                                                                        |
| Non-security reliability issues           | Performance, availability, stale data, failed requests, crashes, errors, or downtime without a demonstrated security impact.                                                                                                                                                                                                              |
| Theoretical or unactionable reports       | AI-generated reports without human validation, broad scanner output, missing reproduction steps, speculative impact, or reports that do not identify a specific affected Nova asset.                                                                                                                                                      |
| Already known or duplicate issues         | Publicly disclosed, already reported, already known, already accepted, or duplicate findings.                                                                                                                                                                                                                                             |

## Prohibited Conduct

The following activity is not authorized by this policy and may disqualify a report:

* Phishing, social engineering, vishing, smishing, impersonation, or attempts to trick Nova users, employees, contractors, partners, or support channels.
* Sending live phishing links, malware, credential-harvesting pages, malicious attachments, or links that could harm Nova users or staff. Use screenshots, inert text, sanitized domains, or a safe proof of concept instead.
* Denial of service, DDoS, stress testing, destructive testing, spam, mass account creation, bulk automation, credential stuffing, brute force attacks, or rate-limit abuse.
* Accessing, copying, storing, modifying, deleting, transferring, freezing, signing with, or attempting to control funds, wallets, devices, accounts, credentials, tokens, logs, or data that you do not own.
* Attempting to obtain, use, or submit seed phrases, private keys, recovery phrases, passcodes, backup codes, signing payloads, session tokens, API credentials, or other secrets.
* Persistence, lateral movement, privilege escalation beyond what is necessary to demonstrate the issue, data exfiltration, extortion, threats, harassment, or unlawful conduct.
* Testing against third-party services, infrastructure, apps, networks, providers, or people without their explicit written authorization.

If you encounter non-public data, secrets, credentials, private user information, or access you did not expect, stop testing immediately, avoid copying or sharing the data, and submit a report through the official channel.

## Submission Process

All vulnerability reports must be submitted through the official form. We do not accept vulnerability reports through social media, public GitHub issues, support chats, app reviews, or unofficial channels.

**Security Submission Form**
[https://tally.so/r/dWEX0A](https://tally.so/r/dWEX0A)

Include:

* Affected Nova-owned asset, URL, endpoint, app version, and device or OS version when relevant.
* Clear reproduction steps and expected versus observed behavior.
* A proof of concept that is safe, minimal, and non-destructive.
* The security boundary bypassed and the real-world user or Nova impact.
* Relevant timestamps, request IDs, transaction signatures, public wallet addresses, screenshots, logs, or videos where useful.
* Confirmation that you used only your own accounts, wallets, devices, data, and funds.

Do not include seed phrases, private keys, passcodes, backup codes, recovery phrases, real user credentials, live phishing links, malware, or secrets in a report.

Incomplete, spammy, automated, AI-generated, or non-actionable submissions may be closed without response.

## Rewards

Nova may offer monetary rewards for valid reports at Nova's sole discretion.

To be eligible for consideration, a report must:

* Be the first complete and actionable report Nova receives for the issue.
* Demonstrate an exploitable security vulnerability with real-world impact to Nova users or Nova-owned production systems.
* Affect an in-scope, current production Nova asset.
* Include reliable reproduction steps and a safe proof of concept.
* Be reported privately through the official submission form.
* Comply with this policy from discovery through disclosure.

Rewards are:

* Not guaranteed.
* Severity-based and determined solely by Nova.
* Paid only after validation and, when needed, remediation.
* Not paid for duplicates, known issues, public disclosures before authorization, out-of-scope findings, prohibited conduct, or reports that only describe abuse of open public APIs.
* Subject to sanctions, tax, payment, identity, and legal restrictions where applicable.

Nova may decline, reduce, or withhold rewards or public credit for reports that violate this policy, contain unsafe content, are repeatedly ineligible, are submitted in bad faith, or cannot be legally paid.

## Disclosure Rules

Do not publicly disclose, discuss, sell, transfer, or share vulnerability details before Nova confirms that a fix has been deployed or explicitly authorizes disclosure in writing.

For user protection, Nova may not publicly confirm, discuss, or disclose security issues until investigation is complete and any necessary updates are generally available.

Public disclosure before authorization, repeated reopening of final decisions, harassment, threats, spam, or attempts to pressure Nova may disqualify a report and end participation in this program.

## Legal Safe Harbor

Nova supports good-faith security research that follows this policy.

If you:

* Act in good faith,
* Stay within the scope and conduct limits above,
* Avoid privacy violations, service disruption, data exfiltration, social engineering, phishing, and harm to users,
* Stop testing and report promptly if you encounter non-public data or unexpected access, and
* Report the issue privately through the official submission form,

then Nova will not initiate legal action against you for accidental, good-faith violations of this policy that are directly related to your in-scope research.

This safe harbor does not apply to:

* Activity outside this policy,
* Activity against third-party systems, people, infrastructure, providers, or assets,
* Unlawful conduct,
* Intentional harm,
* Phishing or social engineering,
* Public disclosure before authorization,
* Extortion, threats, harassment, or coercion,
* Accessing, copying, retaining, sharing, altering, or destroying data that is not yours, or
* Attempts to move, access, freeze, sign with, or control funds or wallets that are not yours.

Nova cannot authorize research against third-party systems and cannot bind third parties, law enforcement, regulators, app stores, infrastructure providers, blockchain networks, or other entities.

Nova may update, pause, or terminate this policy at any time. Changes will not retroactively remove safe harbor for good-faith research that complied with the policy in effect at the time of testing.
