Legal
Security and vulnerability disclosure
If you have found a vulnerability in Novix, please tell us before telling anybody else. This page is what /.well-known/security.txt points at.
How to report
Email support@getnovix.ai. Tell us what you found, how to reproduce it, and what you think the impact is. A rough report beats no report: if you are not sure whether something counts, send it anyway.
If a report contains customer data you came across, say so and do not attach it. We will work out what we need.
What we commit to
Novix is a small company, so this is short and it is all true:
- We acknowledge your report within three working days.
- We tell you what we found when we have looked, and what we are going to do about it.
- We tell you when it is fixed.
- We credit you by name or handle if you want that, and stay quiet about you if you do not.
- We will not pursue or support legal action against you for research done in line with this page.
There is no bounty programme and no payment. We would rather say that plainly than imply one exists.
In scope
getnovix.aiandapp.getnovix.ai, including the API under/api.- The embeddable chat widget and the hosted report form.
- The published packages
@novix-ai/cliand@novix-ai/mcp-server. - Anything about how Novix handles a workspace’s code, tickets, credentials or attachments, including one workspace reaching another’s data.
Out of scope
- Our vendors’ own products. Report those to them; the list is on subprocessors.
- Anything requiring physical access, a stolen device, or social engineering of our staff or customers.
- Denial of service, load testing, and automated scanning heavy enough to affect other people. Please do not.
- Reports from a scanner with no working proof, and findings that are configuration opinions rather than a way in.
- A tool connected to Novix by a customer behaving as that customer configured it. That is their setting, not our bug.
Please do not
- Access, change or keep data that is not yours. If you reach somebody else’s data by accident, stop, and tell us what you saw.
- Run anything destructive, or anything that degrades the service.
- Publish the details until it is fixed, or until 90 days have passed and we have gone quiet. If we are slow, say so and we will agree a date.
What we already do
So you know where to look, and because a security questionnaire asks:
- A person approves every code change. Novix opens a pull request and stops. It never merges on its own.
- Credentials are encrypted at rest and are never mixed between workspaces.
- Attachments are in a private bucket, reachable only through Novix’s own token-scoped routes.
- No third-party analytics script runs on the pages that render other companies’ customer tickets. Our product analytics are first-party.
- Every privileged action is in an audit log that nothing in the product can edit or delete.
- A drafted fix runs in a throwaway container, never on our own machines or yours.
What we do with data, and who else touches it, is on privacy and subprocessors.
What we do not have
We do not hold a SOC 2 report, an ISO 27001 certificate, or any other third-party security or accessibility audit. Novix is small enough that you would be reading an audit of a handful of people. If your review needs one, tell us where you are in your process and we will tell you honestly where we are, rather than implying we have something we do not.
We also have no bug bounty, which is above, and no dedicated security team. One person reads this mailbox.
If something does go wrong
There is a written procedure and we read it before we need it. If an incident touches data we hold for a workspace, we tell that customer without undue delay with what they need to meet their own obligations. If it touches Novix account data, we are the controller and we notify the people affected, and a supervisory authority within 72 hours where the law requires it. The full version is in the privacy policy and our DPA.