NovaHR Vulnerability Disclosure Policy
Version: 1.0
Effective date: [to be confirmed]
NovaHR stores sensitive employee and payroll data, and we take security reports seriously. We welcome good-faith security research and will not pursue legal action against researchers who follow this policy.
1. Scope
In scope:
- The NovaHR web application at novabos.co.za and its subdomains and its APIs.
Out of scope:
- Denial of service, load, or stress testing;
- Social engineering, phishing of NovaHR staff or customers;
- Physical attacks;
- Third-party services we use (Supabase, Vercel, Resend); report those to the vendor;
- Automated scanning that degrades service;
- Accessing, modifying, or deleting data that is not your own test data. If you encounter another tenant's data, stop immediately and report it.
2. Rules of Engagement
- Test only against accounts and tenants you created yourself (a free trial is sufficient);
- Do not exfiltrate data: a minimal proof of concept (e.g. one record ID, a redacted screenshot) is enough;
- Do not degrade the service for others;
- Give us reasonable time to remediate before public disclosure (see section 5);
- Comply with applicable law, including the Cybercrimes Act 19 of 2020; this policy is our authorisation for good-faith research within scope, which we believe removes the "unlawfulness" element for such research.
3. How to Report
Email support@novabos.co.za with the subject "SECURITY REPORT", including:
- Description of the vulnerability and its impact;
- Steps to reproduce (URLs, request/response samples, screenshots);
- Your assessment of severity;
- How you would like to be credited (optional).
Please encrypt sensitive details if possible [PGP key: to be confirmed].
4. What We Commit To
- Acknowledge your report within 3 business days;
- Provide an initial assessment within 10 business days;
- Keep you informed of remediation progress;
- Remediate confirmed vulnerabilities according to severity (critical: as fast as possible, target 7 days; high: 30 days; medium/low: 90 days);
- Credit you (with your consent) once fixed. We do not currently run a paid bug bounty.
5. Coordinated Disclosure
We ask that you do not publicly disclose details until we confirm remediation or 90 days have passed since your report, whichever comes first. If a report affects customer personal information, our Data Breach Response Policy and POPIA notification duties apply.
6. Safe Harbour
We will not initiate legal action or law enforcement referral against researchers who make a good-faith effort to comply with this policy. If a third party initiates action, we will make it known that your activities were conducted under this policy.