NomadPilot

Vulnerability Disclosure Policy

Last updated 20 July 2026

Reporting a vulnerability

If you believe you've found a security vulnerability in NomadPilot or Atlas, please report it to [email protected] (subject line "Security report"). Include as much detail as you can — steps to reproduce, affected URL/endpoint, and potential impact — so we can triage quickly.

Our commitment

Scope

In scope: nomadpilot.app and its subdomains, and the Atlas relocation platform. Out of scope: third-party services we integrate with (Stripe, PayPal, Supabase, etc.) — please report those directly to the provider.

Please don't

Safe harbor

Activity conducted consistent with this policy is authorized under the Computer Fraud and Abuse Act (and equivalent state/foreign laws), and we will not pursue action against researchers acting in good faith within this policy's scope and guidelines.