1. Why this page exists
Security researchers find things we miss. We would rather hear about a weakness from you than from a client, so this page sets out how to tell us and what we will do about it.
This policy covers the Meridian platform, the Polaris and Aurora applications, the Meridian Bar website assistant, the AutoFile browser extension, our public APIs and this website.
2. How to report
Email security@thenovasystem.com. Our machine readable contact details are published at /.well-known/security.txt under RFC 9116.
Tell us what you found, where you found it, and the steps to reproduce it. A short proof of concept helps more than a scanner report. Tell us if you believe client data was exposed, and stop testing at that point.
3. What we commit to
We aim to acknowledge a report within two business days and to give you an initial assessment within ten business days.
We will keep you informed while we fix it, and we will tell you when the fix is live. If we decide not to act on a report, we will say so and explain why rather than going quiet.
We do not run a paid bug bounty today. That is the honest position rather than an implied promise of payment. With your permission we will credit you by name once the issue is fixed.
4. Safe harbour
If you make a good faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your testing as authorised for the purposes of the Canadian Criminal Code provisions on unauthorised use of a computer and any applicable computer misuse law.
This protection is ours to give. It cannot cover the rights of third parties, including our clients and our sub-processors.
5. What we ask of you
Do not access, modify, download or retain any data that is not your own. If you encounter client data, stop, report it, and delete anything you have.
Do not degrade the service. No denial of service testing, no load or stress testing against production, and no spam or automated scanning that would disrupt real practices.
Do not use social engineering, phishing or physical intrusion against our staff, our clients or our suppliers.
Give us a reasonable time to fix the issue before publishing. We aim to resolve confirmed reports within ninety days and we are happy to coordinate a publication date with you.
6. Out of scope
Reports generated purely by an automated scanner with no demonstrated impact, missing best practice headers with no exploit path, self inflicted issues requiring a compromised device or browser extension, social engineering, physical attacks, and issues in third party services we do not control.
Anything that requires a user to be already compromised, or that only affects unsupported browsers or end of life systems, is also out of scope.
7. Client data comes first
If a report shows that client information was accessible, we treat it as a security incident from the moment we confirm it. The Incident Response and Breach Notification Policy then applies, including our obligations under Canadian privacy law.
8. Related documents
The controls themselves are described in the Security Policy. Our processing commitments to firms are in the Data Processing Addendum. Service status and incident history are on the Status page.