Nord Security · Vulnerability Disclosure

Nord Security Vulnerability Disclosure

Vulnerability disclosure

Nord Security runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CybersecurityThreat IntelligenceDark Web MonitoringAttack Surface ManagementBreach IntelligenceVPNPassword ManagementNetwork SecurityZero TrustPrivacyMCPAgent SkillsgRPCCompany
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
mailto:support@nordlayer.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-01'
method: searched
probe: true
source: https://nordlayer.com/.well-known/security.txt
policy: []
contact:
- mailto:support@nordlayer.com
security_txt:
  url: https://nordlayer.com/.well-known/security.txt
  file: well-known/nord-security-nordlayer-security.txt
  http_status: 200
  fields:
    canonical: https://nordlayer.com/.well-known/security.txt
    contact: mailto:support@nordlayer.com
    expires: '2026-12-31T00:00:00Z'
    preferred_languages: en
  gaps:
  - No `Policy:` field — the file gives a contact but points at no disclosure policy.
  - No `Encryption:`, `Acknowledgments:` or `Hiring:` fields.
  - >-
    Published only on the NordLayer product domain (and its api. host). nordsecurity.com,
    nordstellar.com, nordpass.com and nordvpn.com all return 404/403 for /.well-known/security.txt,
    so the corporate parent and the other four products have no RFC 9116 contact.
bug_bounty:
  status: not-publicly-listed
  historical: true
  platform: HackerOne
  documented_by:
  - https://nordvpn.com/blog/nord-security-bug-bounty-launch/
  - https://nordvpn.com/blog/bug-bounty-program-launch/
  - https://nordvpn.com/blog/bug-bounty-results/
  note: >-
    Nord Security ran a public HackerOne program from December 2019 (launched for NordVPN, extended
    in 2021 to NordPass and NordLocker and later NordLayer), with published payouts up to $50,000 for
    critical findings. As of this probe the `nordsecurity` handle no longer resolves on HackerOne —
    both the program page and the HackerOne GraphQL team lookup return not-found — so the program is
    either private/invitation-only or retired. Recorded as historical, not as a live public program.
evidence:
- source: https://nordlayer.com/.well-known/security.txt
  kind: security.txt
  http_status: 200
  fetched: '2026-08-01'
- source: https://api.nordlayer.com/.well-known/security.txt
  kind: security.txt
  http_status: 200
  fetched: '2026-08-01'
  note: byte-identical duplicate served from the API host
- source: https://hackerone.com/nordsecurity
  kind: bug-bounty-probe
  http_status: 404
  fetched: '2026-08-01'
- source: 'https://hackerone.com/graphql {team(handle:"nordsecurity")}'
  kind: bug-bounty-probe
  http_status: 200
  result: 'NOT_FOUND — "Team does not exist" (control handle "security" resolves)'
  fetched: '2026-08-01'