Introduction
At Nomba, the security of our systems, data, and customers is a top priority. We are a PCI-DSS and ISO 27001 certified company committed to maintaining the highest standards of information security across all our products and services.
We recognize that independent security researchers play a valuable role in keeping our platform safe. This Security Disclosure Policy provides guidelines for conducting vulnerability research and explains how to report potential security issues to us. We welcome responsible disclosure from researchers acting in good faith and in accordance with this policy.
Scope
In-Scope Assets:
- Nomba web dashboard (dashboard.nomba.com and associated subdomains)
- Nomba APIs and backend services
- Nomba mobile applications (iOS and Android)
- POS terminal systems and firmware
- Cloud infrastructure and storage services
Out-of-Scope Items:
- Social engineering attacks (phishing, vishing, pretexting) against Nomba employees or customers
- Denial-of-service (DoS/DDoS) attacks
- Third-party services, applications, or websites not owned by Nomba
- Physical attacks against Nomba offices, data centres, or infrastructure
- Attacks against Nomba employees' personal devices or accounts
Vulnerability Classification & Bounty Rewards
Vulnerabilities are classified based on their CVSS (Common Vulnerability Scoring System) score. Bounty amounts are determined by severity and impact. Final amounts are at Nomba's discretion.
| Severity | CVSS Score | Bounty | Examples |
|---|---|---|---|
| Critical | 9.0 – 10.0 | $250 | Remote code execution, authentication bypass, payment manipulation, mass data exfiltration, public storage buckets exposing PII |
| High | 7.0 – 8.9 | $75 | Privilege escalation, insecure direct object references (IDOR), SQL injection, credential exposure |
| Medium | 4.0 – 6.9 | $25 | Stored cross-site scripting (XSS), cross-site request forgery (CSRF), information disclosure |
| Low | 0.1 – 3.9 | $10 | Reflected XSS, verbose error messages, missing security headers |
How to Report
Please submit all vulnerability reports via email to security@nomba.com.
Your report should include:
- A clear description of the vulnerability and its potential impact
- Detailed steps to reproduce the issue
- An impact assessment describing what an attacker could achieve
- Proof of concept (PoC), screenshots, or video demonstrations
- Affected URLs, endpoints, or system components
- Your recommended remediation, if applicable
Data Handling Rules
When conducting security research, you must adhere to the following data handling requirements:
- Access the minimum amount of data necessary to demonstrate the vulnerability
- Do not bulk download, copy, or exfiltrate data from any Nomba system
- Do not access, store, or transmit biometric data, KYC documents, or personally identifiable information (PII) beyond what is strictly necessary for the proof of concept
- Delete all data obtained during testing immediately after submitting your report
- Where possible, use hash values or redacted screenshots as proof instead of raw data
- Never share discovered data with any third party
Rules of Engagement
- Do not perform destructive testing: avoid actions that could degrade, disrupt, or damage Nomba systems or data
- Do not access other users' accounts or data beyond the minimum needed for a proof of concept
- Do not use social engineering techniques against Nomba employees, contractors, or customers
- Do not conduct denial-of-service (DoS/DDoS) attacks
- Do not attempt physical intrusion of Nomba facilities
- Do not use automated scanning tools in a manner that generates excessive traffic
- You must be at least 18 years of age to participate in this program
Response Timeline
We are committed to responding promptly to all security reports:
- Acknowledgement: Within 48 hours of receiving your report
- Triage: Within 7 business days, we will confirm receipt and begin initial assessment
- Severity Assessment: Within 10 business days, we will assign a severity rating and communicate our findings
- Bounty Payment: Within 30 days of a validated fix being deployed
We may contact you for additional information or clarification during the triage process. Please respond promptly to ensure timely resolution.
Safe Harbor
Nomba supports safe harbor for security researchers who act in good faith and in accordance with this policy. We will not pursue legal action against researchers who:
- Conduct research strictly within the scope defined in this policy
- Report vulnerabilities directly to Nomba and do not disclose them publicly or to any third party without written approval
- Make a good-faith effort to avoid privacy violations, data destruction, and service disruption
- Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue
If legal action is initiated by a third party against you for activities conducted in accordance with this policy, Nomba will take steps to make it known that your actions were authorised under this program.
Eligibility & Exclusions
- Multiple vulnerabilities arising from a single root cause will be treated as one finding for bounty purposes
- Bounty rewards are paid to the first researcher who reports a previously unknown vulnerability
- Duplicate reports will not be eligible for a bounty. The first valid report takes precedence
- Current or former Nomba employees, contractors, and their immediate family members are not eligible
- Researchers must not publicly or privately disclose the vulnerability or the contents of their submission to any third party without Nomba's prior written approval. This applies both before and after remediation
- Vulnerabilities in out-of-scope assets or that result from out-of-scope testing methods are not eligible
- Reports generated solely by automated tools without manual verification are not eligible
- Researchers must comply with all applicable laws in their jurisdiction
Contact
For all security-related reports and enquiries, please contact us at:
We appreciate the efforts of security researchers in helping keep Nomba and our customers safe. Thank you for your responsible participation in our security disclosure program.
