Use the smallest safe proof.
- Test only Novex-owned surfaces.
- Use a test account where possible.
- Minimize requests and data access.
- Sanitize screenshots, logs, and reproduction steps.
- Stop after confirming the issue safely.
Responsible disclosure Novex-owned surfaces
If you believe you found a vulnerability in a Novex-owned surface, report it privately. Protect users, stop before impact, and keep exploit details out of public issues and chats. Novex will never ask for a seed phrase, private key, remote-wallet approval, or unsolicited transfer.
NEXT ACTIONBEGIN
Contact the verified Novex community and ask a moderator for the private security-report path.
This guide collects and transmits nothing.
Disclosure sequence
The public opening stays deliberately small. Detailed evidence moves only after a verified private reporting path is established.
Provide the affected Novex-owned URL or product.
Use a broad issue category without publishing exploit details.
Ask a verified Novex moderator where to continue securely.
Share reproduction steps privately with secrets and personal data removed.
Safe-research boundary
Research permission stops where another user, production data, funds, availability, or a third-party service could be affected.
Private report packet
A strong report makes the issue repeatable without including credentials, active secrets, another user’s information, or unnecessary production data.
Never send seed phrases, private keys, credentials, signatures, tokens, or live access material.
Redact wallet identifiers, account details, personal information, positions, and private trading records.
If exploitation may be occurring, stop testing and identify the private report as urgent.
Current release controls
These controls reduce specific risks. They do not make the software invulnerable and do not replace an independent high-assurance review.
Security headers, same-origin request rules, fixed public routes, secret scans, and production build gates constrain the Hub release.
ACTIVENovex Swap isolates wallet code from the Hub, pins its launch fee server-side, revalidates firm quotes, and requests exact EVM approvals.
ACTIVEScanner, Intelligence, and Magnets do not receive wallet, signing, order, custody, or execution authority from the Hub.
SEPARATEThe future high-assurance review must cover transaction construction, providers, dependencies, deployment, wallets, monitoring, and incident response.
NOT STARTEDNo honest audit can guarantee that software is unhackable. Publish only claims supported by completed evidence.
Response targets
Severity, reproducibility, third-party dependencies, and required remediation determine the final timeline.
Target for acknowledging a complete private report.
Target for an initial triage update after a complete report.
Resolution timing depends on impact, complexity, and affected vendors.
We aim to acknowledge a complete private report within three business days and provide an initial triage update within seven business days. These service targets are not a guarantee or bounty offer, and they do not create a safe-harbor agreement.
Verified private path
Begin with the affected Novex URL and broad issue class only. Ask a moderator in the verified Novex Finance community for the private security-report path.