Security

Security & Vulnerability Disclosure

Last updated: June 1, 2026 · NomadTVs

We take the security of our service and our customers seriously. If you believe you have found a security vulnerability affecting nomadtvs.com or any associated infrastructure, we welcome your report under the terms below.

Scope

In scope:

  • nomadtvs.com and all subdomains
  • Payment processing flows on this domain
  • Authentication and account management endpoints

Out of scope:

  • Third-party services (Cloudflare and payment processors) — report directly to them
  • Volumetric denial-of-service attacks (DDoS)
  • Social engineering of staff or customers
  • Physical attacks on our infrastructure
  • Issues already known to us or publicly disclosed
  • Best-practice findings without demonstrated impact (e.g. missing security headers on static pages without sensitive data)

How to report

Email [email protected] with:

  1. A clear description of the vulnerability
  2. Steps to reproduce (proof-of-concept, screenshots, request/response captures)
  3. Impact assessment — what an attacker could achieve
  4. Your contact details (we will acknowledge within 72 hours)

If your report is sensitive, you may encrypt it. Request our PGP public key in your first message.

Safe Harbor

We will not pursue legal action against researchers who:

  • Make a good-faith effort to comply with this policy
  • Avoid privacy violations, destruction of data, and interruption of service
  • Do not access, modify, or exfiltrate data beyond what is necessary to demonstrate the vulnerability
  • Give us reasonable time to remediate before any public disclosure (we target 90 days)

What to expect

  1. Acknowledgment within 72 hours of your report
  2. Triage and validation within 7 business days
  3. Remediation timelines depend on severity:
    • Critical: 7 days
    • High: 30 days
    • Medium: 60 days
    • Low: 90 days
  4. Public acknowledgment (with your permission) once remediation is verified

Bug bounty

We do not currently operate a paid bug bounty programme. Verified, high-quality reports may be acknowledged publicly (see Acknowledgments below) and may receive a small token of appreciation at our discretion.

Acknowledgments

Researchers who have responsibly disclosed valid security issues will be listed here with their consent.

Machine-readable contact

See /.well-known/security.txt (RFC 9116).

This policy is provided in good faith but does not waive any rights we may have under applicable law. We reserve the right to update this policy at any time. Material changes will be announced via this page.

Get Started — From $4.75/mo
WhatsApp Telegram