At Nicoka, we take data security seriously and strive to ensure a secure experience when users use our products. When reported properly, we investigate all legitimate security vulnerabilities and resolve identified issues where appropriate. We have adopted a vulnerability disclosure program to encourage the reporting of security vulnerabilities.
Share the security issue with us without making it public at any time, including, but not limited to, not making it public on social media, discussion forums, mailing lists, and other forums. Do not engage in security research that involves: Potential or actual harm to users, businesses, individuals, systems, data, or applications. Violation of privacy or data confidentiality rights. Social engineering (including, but not limited to, phishing). Disruption or interruption of our services. Port scans on our networks or DDoS attacks. If you comply with our program rules, we will not pursue legal action against you or ask law enforcement to investigate you, unless we have reason to believe you did not act in good faith.
We do not offer bug bounties or rewards.
You can send the vulnerability you wish to disclose to vulnerabilities@nicoka.com or use the "Feedback" button if you are logged in. Please answer the following questions in your email:
What type of vulnerability is it?
What steps are required to reproduce the vulnerability?
Who would be able to exploit the vulnerability and what would they gain from it?
Feel free to include attachments (Screenshots, Logs, etc).
We will respond to your email within two weeks and provide updates on the status of the vulnerability.