Security

Responsible Disclosure Policy

Last updated: August 2026

Nordic Infrastructure Lab takes the security of our systems seriously. If you have identified a potential vulnerability in systems operated by Nordic Infrastructure Lab, we encourage you to disclose it responsibly. This policy describes how to report a vulnerability, what you can expect from us, and what we ask of you.

Scope

This policy applies to vulnerabilities identified in systems directly operated by Nordic Infrastructure Lab, including our public-facing web properties and any infrastructure explicitly identified as in-scope for security research.

This policy does not authorize testing of third-party systems, customer infrastructure, or any systems not explicitly operated by Nordic Infrastructure Lab. Unauthorized testing of out-of-scope systems is not covered by this policy and may violate applicable law.

How to Report

Send your report to [email protected] with the subject line 'Security Disclosure'. Please include a clear description of the vulnerability, the steps required to reproduce it, the potential impact, and any supporting evidence (screenshots, proof-of-concept code, or logs).

If you believe the vulnerability is sensitive, you may request our PGP public key for encrypted communication before submitting your report.

What We Commit To

We will acknowledge receipt of your report within 48 hours.

We will provide an initial assessment of the report within 7 business days.

We will keep you informed of our remediation progress and notify you when the vulnerability has been resolved.

We will not pursue legal action against researchers who discover and report vulnerabilities in good faith and in accordance with this policy.

We will acknowledge your contribution in our security acknowledgements, unless you prefer to remain anonymous.

What We Ask of You

Do not access, modify, or delete data that does not belong to you.

Do not perform denial-of-service attacks or disrupt services.

Do not use automated scanning tools against our infrastructure without prior written authorization.

Do not disclose the vulnerability publicly until we have had a reasonable opportunity to remediate it. We aim to resolve critical vulnerabilities within 90 days of disclosure.

Act in good faith. We will extend the same good faith to you.

Out of Scope

The following are considered out of scope: social engineering attacks, physical security issues, denial-of-service attacks, spam or phishing campaigns, vulnerabilities in third-party services we use (report those to the relevant vendor), and issues that require physical access to our infrastructure.

Contact

For security disclosures, email [email protected] with the subject line 'Security Disclosure'. For general inquiries, use the contact page.

[email protected]