Security Research and Vulnerability Disclosure Policy

Novelcrafter welcomes responsible reports of security vulnerabilities in systems that we operate.

Important: This program offers discretionary rewards for useful, novel, and well-researched findings. We don’t guarantee monetary rewards for all reports.

Reporting a Vulnerability

Send security reports to support@novelcrafter.com with:

Please allow us time to investigate and fix issues before public disclosure.

Scope

You may test publicly accessible Novelcrafter systems following this policy.

Please avoid:

If you accidentally access sensitive data: Stop testing immediately, don’t retain the data, and contact us.

Staging Access

Our staging and other non-public environments are out of scope by default.

Security researchers may request access to a temporary, separate environment before testing. Receiving separate environment access does not guarantee a reward.

Tell us what you would like to test and how you intend to test it. Testing is authorized only after we have given you written approval. Our approval may restrict the systems, accounts, methods, or time period you may use.

Rewards and Eligibility

We may offer rewards for reports identifying previously unknown, reproducible security vulnerabilities in our systems. We determine eligibility and amounts case-by-case.

Please share vulnerability information directly rather than withholding it or making disclosure conditional on payment.

Automated and Low-Quality Reports

The use of automated and AI-assisted tools for your report are allowed, but you are fully responsible for validating every report before submitting it.

We don’t offer rewards for:

Repeated submission of fabricated, misleading, or persistently low-quality reports may be ignored or blocked.

Authentication and Third-Party Services

Novelcrafter uses third-party services for parts of the platform, including user registration and authentication.

Out of scope: Vulnerabilities that exist solely within a third-party provider’s service or infrastructure should be reported to that provider instead. This includes vulnerabilities in the third-party service itself, even where that service is presented through a Novelcrafter-branded domain or site (e.g. via an iframe).

In scope: Issues caused by our integration or configuration of third-party services may be reported to us, such as incorrect authorization decisions, account-linking problems, session handling, token leakage.

Our policy does not authorize you to test infrastructure belonging to a third party.