# Noddr — security contact and disclosure policy. # # Noddr approves a coding agent's tool calls with a head gesture, so it # sits in a privileged path: something that says yes to commands running # on a user's machine. Reports about that path are especially welcome. # # Good-faith researchers acting within the published scope have safe # harbour. That commitment applies from the moment you write to us, not # from the moment we agree with your assessment. Full terms, scope, threat # model, and the current list of known issues: https://noddr.cloud/security # # There is no bug bounty and we do not pay for reports. Said here so you # can decide before spending your time, not after. Contact: mailto:security@noddr.cloud Expires: 2027-07-29T00:00:00.000Z Policy: https://noddr.cloud/security Canonical: https://noddr.cloud/.well-known/security.txt Preferred-Languages: en