Vulnerability Disclosure Policy
This policy explains how to report a security vulnerability in nodes.inc or in a customer-facing service NODES operates, what is in scope, and the safe harbor we extend to researchers who follow it.
Scope
In scope: nodes.inc and the customer-facing services NODES operates.
Out of scope: customer deployments. Those run inside each customer’s own VPC and are the customer’s property. Test only systems you are authorized to test, and do not test against a customer environment.
Safe harbor
If you follow this policy, we treat your research as authorized and we will not pursue legal action against you for it. Good-faith research means you stop at the minimum access needed to demonstrate the issue, you do not access or alter data that is not yours, you do not degrade the service for others, and you give us a reasonable window to fix the issue before you disclose it publicly.
How to report
Email support@nodes.inc. Include the affected system, the steps to reproduce the issue, and the potential impact. Do not send personal data you may have accessed during testing. Describe it instead.
What to expect
We acknowledge reports within 3 business days. After acknowledgment we investigate, and we tell you when the issue is resolved or when we need more information.
NODES does not operate a bug bounty program, and no bounty is promised for reports. We thank researchers who help us keep the service safe, and we ask for the chance to fix what you find before it becomes public.
Last reviewed: July 2026.