Reporting a security issue.
If you believe you have found a security issue affecting this website, we want to hear from you. This page explains how to report it and what this site does to reduce risk.
Responsible disclosure
Send a report to info@novadigitalsolutions.io with the word "security" in the subject line. Please include the affected URL, what you observed, and the steps to reproduce it.
We ask that you give us a reasonable opportunity to investigate and remediate before publishing, and that you avoid privacy violations, service degradation, or destruction of data while testing.
We will acknowledge a credible report, keep you informed while we investigate, and confirm when the issue is resolved.
Scope
This page covers this website. It does not cover NOVA products or systems, which are not publicly accessible and are not in scope for testing.
How this site reduces risk
The site is deliberately small in attack surface: it is statically generated, has no login, no user accounts, no public administrative interface, and no database.
Responses are served with a strict content security policy, strict transport security, and restrictive referrer, framing, and permissions policies.
Dependencies are pinned to exact versions, and dependency auditing, secret scanning, and content scanning run automatically in our build pipeline before any release can proceed.
What we ask you not to do
Please do not run denial-of-service or high-volume automated testing against the site, do not attempt to access data belonging to others, and do not use social engineering against anyone associated with NOVA.