NOGA
SECURITY REPORTING
NOGA takes the security of its website and technology seriously. If you believe you have found a security vulnerability affecting a NOGA-owned public system, report it through the Security report form on this page.
What to include
- A clear description of the issue and its potential impact.
- The affected public URL or system identifier.
- Steps that allow NOGA to reproduce the issue without exposing personal data, credentials, or sensitive building information.
- A way for NOGA to contact you.
Safe reporting boundaries
Do not access, alter, download, retain, or disclose personal information; do not obtain or use credentials; do not disrupt services; do not test connected buildings, physical-access systems, resident systems, devices, or third-party systems; and do not use social engineering, denial-of-service techniques, destructive testing, or persistence. Stop testing when you confirm a possible issue and report it.
Submitting a report does not authorise activity that is unlawful, unsafe, outside these boundaries, or harmful to people, property, data, or services. NOGA will assess good-faith reports and may contact the reporter for clarification. NOGA does not promise a reward or a specific response or remediation time.
Confidentiality
Give NOGA a reasonable opportunity to investigate and address a reported issue before any public disclosure. Do not include exploit code, secrets, personal data, or sensitive physical-space details unless NOGA specifically requests them through a secure channel.
Security report form
Online submission is not yet available. The form will be activated after its secure delivery service is ready.
Enter NOGA