Security Research and Vulnerability Disclosure Policy
Novelcrafter welcomes responsible reports of security vulnerabilities in systems that we operate.
Important: This program offers discretionary rewards for useful, novel, and well-researched findings. We don’t guarantee monetary rewards for all reports.
Reporting a Vulnerability
Send security reports to support@novelcrafter.com with:
- Affected URL, endpoint, or feature,
- Clear reproduction steps,
- The security impact,
- A minimal proof of concept or supporting evidence,
- Required account types or special conditions.
Please allow us time to investigate and fix issues before public disclosure.
Scope
You may test publicly accessible Novelcrafter systems following this policy.
Please avoid:
- Access, modify, copy, or delete another user’s data,
- Denial-of-service, load, or resource-exhaustion testing,
- Credential stuffing, password spraying, or brute force attacks,
- Phishing, social engineering, spam, or physical-security testing,
- Disrupting Novelcrafter or other users,
- Establishing persistence or accessing unrelated systems,
- Conducting high-volume automated scanning,
- Testing third-party systems without authorization from their owner.
If you accidentally access sensitive data: Stop testing immediately, don’t retain the data, and contact us.
Staging Access
Our staging and other non-public environments are out of scope by default.
Security researchers may request access to a temporary, separate environment before testing. Receiving separate environment access does not guarantee a reward.
Tell us what you would like to test and how you intend to test it. Testing is authorized only after we have given you written approval. Our approval may restrict the systems, accounts, methods, or time period you may use.
Rewards and Eligibility
We may offer rewards for reports identifying previously unknown, reproducible security vulnerabilities in our systems. We determine eligibility and amounts case-by-case.
Please share vulnerability information directly rather than withholding it or making disclosure conditional on payment.
Automated and Low-Quality Reports
The use of automated and AI-assisted tools for your report are allowed, but you are fully responsible for validating every report before submitting it.
We don’t offer rewards for:
- Raw scanner or automated-tool output,
- Generic or speculative security advice,
- AI-generated reports that have not been manually validated,
- Fabricated or non-reproducible findings,
- Version-number reports without evidence that the vulnerability is actually exploitable,
- Missing headers or other best-practice recommendations without meaningful security impact,
- Duplicate reports,
- Multiple reports describing the same underlying issue,
- High-volume, low-effort submissions.
Repeated submission of fabricated, misleading, or persistently low-quality reports may be ignored or blocked.
Authentication and Third-Party Services
Novelcrafter uses third-party services for parts of the platform, including user registration and authentication.
Out of scope: Vulnerabilities that exist solely within a third-party provider’s service or infrastructure should be reported to that provider instead. This includes vulnerabilities in the third-party service itself, even where that service is presented through a Novelcrafter-branded domain or site (e.g. via an iframe).
In scope: Issues caused by our integration or configuration of third-party services may be reported to us, such as incorrect authorization decisions, account-linking problems, session handling, token leakage.
Our policy does not authorize you to test infrastructure belonging to a third party.