This section provides legally binding assurances and protections for good-faith security researchers participating in the NOYD Vulnerability Disclosure Program.
NOYD hereby declares and affirms that security research conducted in good faith and in accordance with all terms and conditions of this policy constitutes authorized activity and shall be afforded full legal protection.
+=============================================================================+
| LEGAL SAFE HARBOR DECLARATION |
+=============================================================================+
| |
| NOYD explicitly authorizes the following activities under this policy: |
| |
| [CHECK] Good-faith security research on in-scope targets |
| [CHECK] Testing and probing for vulnerabilities with good-faith intent |
| [CHECK] Reporting identified vulnerabilities through designated channels |
| [CHECK] Publishing technical details after coordinated disclosure |
| [CHECK] Using vulnerability information solely for defensive purposes |
| |
| Such authorized activities shall be deemed: |
| |
| [盾牌] LEGALLY PERMISSIBLE under applicable computer crime laws |
| [盾牌] EXEMPT from civil liability under this policy |
| [盾牌] PROTECTED from third-party legal claims |
| [盾牌] ELIGIBLE for bug bounty rewards and recognition |
| |
+=============================================================================+
This safe harbor provision is intended to comply with and provide protection under:
| Jurisdiction | Applicable Law | Key Provisions |
|---|---|---|
| United States | Computer Fraud and Abuse Act (CFAA), 18 U.S.C. Section 1030 | Section 1030(a)(2) access authorization, Section 1030(d) harm avoidance |
| European Union | NIS2 Directive (2016/1149), GDPR Article 6(1)(f) | Legitimate interest in security research |
| United Kingdom | Computer Misuse Act 1990, Section 3A | Authorized access defense |
| Canada | Computer Fraud Act (S.C. 1985, c. C-46), Section 342.1 | Authorization defense |
| Australia | Criminal Code Act 1995, Division 478 | Authorized computer access |
Legal protection under this policy is conditional and applies only when ALL of the following requirements are satisfied:
/==============================================================================\
MANDATORY COMPLIANCE REQUIREMENTS
\==============================================================================/
1. AUTHORIZED TARGETS
[ ] Testing is confined exclusively to in-scope targets
[ ] No testing on systems explicitly marked as out-of-scope
[ ] No attacks against third-party infrastructure
2. GOOD-FAITH INTENT
[ ] Research conducted to improve security, not exploit vulnerabilities
[ ] No intent to cause harm, obtain unauthorized access, or steal data
[ ] Actions taken are proportionate to the security research purpose
3. COMPLIANCE WITH POLICY
[ ] All testing conducted in accordance with this policy
[ ] No violation of prohibited activities (Section 1.2)
[ ] Responsible disclosure timelines honored
4. DOCUMENTATION
[ ] Comprehensive documentation of findings maintained
[ ] Evidence of good-faith research preserved
[ ] Proof of policy compliance available upon request
5. NO EXFILTRATION OR MISUSE
[ ] No data exfiltrated beyond necessary to demonstrate vulnerability
[ ] No modification or destruction of data or systems
[ ] No persistence established on NOYD systems
[ ] No leveraging of vulnerabilities for unauthorized access
\==============================================================================/
NOYD provides the following specific assurances regarding the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. Section 1030:
NOYD affirms that:
- Security research conducted under this policy is authorized access
- The authorization extends to any automated or manual testing methods
- This authorization is explicitly documented and can be verified
- Any access exceeding authorization must be immediately reported and ceased
NOYD confirms that:
- Researchers may share vulnerability information with NOYD and authorized parties
- Such sharing is protected under this safe harbor provision
- Researchers shall not traffic in access devices obtained through research
NOYD waives its right to initiate civil action under CFAA against researchers who comply fully with this policy, to the maximum extent permitted by law.
If a researcher who has complied with this policy becomes subject to legal action by a third party, NOYD commits to the following:
| Timeline | Action |
|---|---|
| IMMEDIATE (72 hours) | Written confirmation of authorized research status; Documentation of policy compliance; Contact information for NOYD legal counsel |
| MEDIUM-TERM (14 days) | Formal affidavit of authorized research; Technical documentation supporting defense; Expert witness availability if required |
| ONGOING | Continued support throughout legal proceedings; Additional documentation as needed; Coordination with researcher legal team |
NOYD agrees to indemnify and hold harmless researchers who:
- Conduct security research in good faith
- Fully comply with all policy requirements
- Are named as defendants in legal actions arising from authorized research
- Promptly notify NOYD of any legal claims or government inquiries
Legal protection DOES NOT apply under the following circumstances:
| Exception | Description | Consequence |
|---|---|---|
| Prohibited Activities | Violation of Section 1.2 | Full liability restored |
| Out-of-Scope Testing | Testing targets not in program scope | No protection |
| Premature Disclosure | Publishing before coordinated fix | No protection |
| Malicious Intent | Research for harmful purposes | Criminal liability possible |
| Fraudulent Claims | False vulnerability reports | Disqualification + liability |
| Unauthorized Access | Accessing systems beyond authorization | CFAA liability possible |
To invoke safe harbor protection, researchers should maintain:
REQUIRED DOCUMENTATION FOR SAFE HARBOR INVOCATION
==============================================================================
[ ] Dated records of all testing activities
[ ] Screenshots/logs showing test methodology
[ ] Timestamps of vulnerability discovery
[ ] Copies of all communications with NOYD
[ ] Proof of policy compliance (checklist)
[ ] Evidence of good-faith intent
[ ] Documentation of data handling practices
[ ] Records of any third-party involvement
RETAIN FOR: Minimum 3 years from date of last research activity
If a dispute arises regarding:
- Policy Interpretation: Seek clarification via
security@noyd.dev - Compliance Questions: Request written compliance determination
- Safe Harbor Invocation: Provide documentation to NOYD legal counsel
- Third-Party Claims: Contact
legal@noyd.devimmediately
NOYD commits to responding to safe harbor disputes within 14 business days.
- This safe harbor provision survives termination of other policy terms
- NOYD will provide 30 days written notice before materially reducing protections
- Research conducted under prior versions of this policy remains protected
- Safe harbor cannot be unilaterally revoked for past good-faith research
This policy was developed with reference to:
- NIST Computer Security Incident Handling Guide (SP 800-61)
- ISO 29147:2018 - Vulnerability Disclosure
- ISO 30111:2019 - Vulnerability Handling Processes
- FIRST CVSS v3.1 Specification
- Google's Vulnerability Disclosure Policy
- HackerOne Vulnerability Disclosure Guidelines
- EFF Coders' Rights Project
By participating in the NOYD Vulnerability Disclosure Program, you agree to the terms and conditions outlined in this policy.
Document Version: 1.1 | Last Updated: 2025-01-15