Skip to content

Security: noyddev/noyd-vulnerability-program

Security

SECURITY.md


10. Legal Safe Harbor & Immunity

This section provides legally binding assurances and protections for good-faith security researchers participating in the NOYD Vulnerability Disclosure Program.

10.1 Legal Immunity Declaration

NOYD hereby declares and affirms that security research conducted in good faith and in accordance with all terms and conditions of this policy constitutes authorized activity and shall be afforded full legal protection.

+=============================================================================+
|                           LEGAL SAFE HARBOR DECLARATION                      |
+=============================================================================+
|                                                                             |
|  NOYD explicitly authorizes the following activities under this policy:      |
|                                                                             |
|  [CHECK] Good-faith security research on in-scope targets                  |
|  [CHECK] Testing and probing for vulnerabilities with good-faith intent      |
|  [CHECK] Reporting identified vulnerabilities through designated channels     |
|  [CHECK] Publishing technical details after coordinated disclosure           |
|  [CHECK] Using vulnerability information solely for defensive purposes       |
|                                                                             |
|  Such authorized activities shall be deemed:                                  |
|                                                                             |
|  [盾牌] LEGALLY PERMISSIBLE under applicable computer crime laws            |
|  [盾牌] EXEMPT from civil liability under this policy                     |
|  [盾牌] PROTECTED from third-party legal claims                            |
|  [盾牌] ELIGIBLE for bug bounty rewards and recognition                     |
|                                                                             |
+=============================================================================+

10.2 Applicable Law References

This safe harbor provision is intended to comply with and provide protection under:

Jurisdiction Applicable Law Key Provisions
United States Computer Fraud and Abuse Act (CFAA), 18 U.S.C. Section 1030 Section 1030(a)(2) access authorization, Section 1030(d) harm avoidance
European Union NIS2 Directive (2016/1149), GDPR Article 6(1)(f) Legitimate interest in security research
United Kingdom Computer Misuse Act 1990, Section 3A Authorized access defense
Canada Computer Fraud Act (S.C. 1985, c. C-46), Section 342.1 Authorization defense
Australia Criminal Code Act 1995, Division 478 Authorized computer access

10.3 Conditions for Legal Protection

Legal protection under this policy is conditional and applies only when ALL of the following requirements are satisfied:

Mandatory Requirements

/==============================================================================\
                           MANDATORY COMPLIANCE REQUIREMENTS
\==============================================================================/

  1. AUTHORIZED TARGETS
     [ ] Testing is confined exclusively to in-scope targets
     [ ] No testing on systems explicitly marked as out-of-scope
     [ ] No attacks against third-party infrastructure

  2. GOOD-FAITH INTENT
     [ ] Research conducted to improve security, not exploit vulnerabilities
     [ ] No intent to cause harm, obtain unauthorized access, or steal data
     [ ] Actions taken are proportionate to the security research purpose

  3. COMPLIANCE WITH POLICY
     [ ] All testing conducted in accordance with this policy
     [ ] No violation of prohibited activities (Section 1.2)
     [ ] Responsible disclosure timelines honored

  4. DOCUMENTATION
     [ ] Comprehensive documentation of findings maintained
     [ ] Evidence of good-faith research preserved
     [ ] Proof of policy compliance available upon request

  5. NO EXFILTRATION OR MISUSE
     [ ] No data exfiltrated beyond necessary to demonstrate vulnerability
     [ ] No modification or destruction of data or systems
     [ ] No persistence established on NOYD systems
     [ ] No leveraging of vulnerabilities for unauthorized access

\==============================================================================/

10.4 CFAA Compliance Statement

NOYD provides the following specific assurances regarding the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. Section 1030:

Section 1030(a)(2) - Access Authorization

NOYD affirms that:

  • Security research conducted under this policy is authorized access
  • The authorization extends to any automated or manual testing methods
  • This authorization is explicitly documented and can be verified
  • Any access exceeding authorization must be immediately reported and ceased

Section 1030(b) - Trafficking in Access Devices

NOYD confirms that:

  • Researchers may share vulnerability information with NOYD and authorized parties
  • Such sharing is protected under this safe harbor provision
  • Researchers shall not traffic in access devices obtained through research

Section 1030(d) - Civil Remedy Limitation

NOYD waives its right to initiate civil action under CFAA against researchers who comply fully with this policy, to the maximum extent permitted by law.

10.5 Third-Party Claim Defense

If a researcher who has complied with this policy becomes subject to legal action by a third party, NOYD commits to the following:

Timeline Action
IMMEDIATE (72 hours) Written confirmation of authorized research status; Documentation of policy compliance; Contact information for NOYD legal counsel
MEDIUM-TERM (14 days) Formal affidavit of authorized research; Technical documentation supporting defense; Expert witness availability if required
ONGOING Continued support throughout legal proceedings; Additional documentation as needed; Coordination with researcher legal team

10.6 Indemnification

NOYD agrees to indemnify and hold harmless researchers who:

  • Conduct security research in good faith
  • Fully comply with all policy requirements
  • Are named as defendants in legal actions arising from authorized research
  • Promptly notify NOYD of any legal claims or government inquiries

10.7 Exceptions to Legal Protection

Legal protection DOES NOT apply under the following circumstances:

Exception Description Consequence
Prohibited Activities Violation of Section 1.2 Full liability restored
Out-of-Scope Testing Testing targets not in program scope No protection
Premature Disclosure Publishing before coordinated fix No protection
Malicious Intent Research for harmful purposes Criminal liability possible
Fraudulent Claims False vulnerability reports Disqualification + liability
Unauthorized Access Accessing systems beyond authorization CFAA liability possible

10.8 Documentation Requirements

To invoke safe harbor protection, researchers should maintain:

REQUIRED DOCUMENTATION FOR SAFE HARBOR INVOCATION
==============================================================================

[ ] Dated records of all testing activities
[ ] Screenshots/logs showing test methodology
[ ] Timestamps of vulnerability discovery
[ ] Copies of all communications with NOYD
[ ] Proof of policy compliance (checklist)
[ ] Evidence of good-faith intent
[ ] Documentation of data handling practices
[ ] Records of any third-party involvement

RETAIN FOR: Minimum 3 years from date of last research activity

10.9 Dispute Resolution

If a dispute arises regarding:

  1. Policy Interpretation: Seek clarification via security@noyd.dev
  2. Compliance Questions: Request written compliance determination
  3. Safe Harbor Invocation: Provide documentation to NOYD legal counsel
  4. Third-Party Claims: Contact legal@noyd.dev immediately

NOYD commits to responding to safe harbor disputes within 14 business days.

10.10 Policy Amendments and Survival

  • This safe harbor provision survives termination of other policy terms
  • NOYD will provide 30 days written notice before materially reducing protections
  • Research conducted under prior versions of this policy remains protected
  • Safe harbor cannot be unilaterally revoked for past good-faith research

11. Acknowledgments

This policy was developed with reference to:


By participating in the NOYD Vulnerability Disclosure Program, you agree to the terms and conditions outlined in this policy.

Document Version: 1.1 | Last Updated: 2025-01-15

There aren't any published security advisories