Company NoOnes (also referred to as “NoOnes,” “we,” “us,” or “our”) takes steps to improve our product and provide secure solutions for our customers. In this Bug Bounty Policy (“Policy”), we describe applicable cases for our Bug Bounty Program and how it should be used in connection with your use of our website at https://noones.com/, including, but not limited to, the NoOnes Wallet, online Bitcoin trading platform, mobile application, social media pages, or other online properties (collectively, the “Website”), or when you use any of the products, services, content, features, technologies, or functions we offer (collectively, the “Services”). This Policy is designed to help you obtain information about how you can participate in our Bug Bounty Program, which secure research results are applicable, and which benefits you can receive. Please note that our Service offerings may vary by region.
For all purposes, the English language version of this bug bounty policy shall be the original, governing instrument. In the event of any conflict between the English language version of this bug bounty policy and any subsequent translation into any other language, the English language version shall govern and control.
In order to improve NoOnes and the Services, the NoOnes Bug Bounty Program provides our users an opportunity to earn a reward for identifying security related issues.
All such communications should be directed to [email protected]. In your submission please specify full description of the vulnerability and verifiable proof that the vulnerability exists (explanation / steps to reproduce / screenshots / videos / scripts or such other materials).
Violation of any of these rules can result in ineligibility for a bounty.
All findings are evaluated using a risk-based approach.
Before we begin discussing any details related to confirmed issues that you have identified under the Bug Bounty Program, including compensation, etc., you will be required to enter into a Non-Disclosure Agreement with us.
All such rewards are paid by NoOnes. All rewards can be paid only if they are not contrary to applicable laws and regulations, including but not limited to trade sanctions and economic restrictions.
Due to the varying and complex nature of technical issues, we have not established particular timelines for analyzing findings under the Bug Bounty Program. Our analysis is finished only when we have confirmed the existence or absence of a vulnerability.
Certain vulnerabilities are considered out-of-scope for the Bug Bounty Program. Those out-of-scope vulnerabilities include, but are not limited to:
Vulnerabilities that enable attackers to authenticate, add, delete or modify any of the content on the blog.noones.com, noones.com/blog.