Responsible Disclosure
Security & Vulnerability Disclosure Policy
If you have found a security issue in a Norvet MSP property, this page tells you how to report it, what is in scope, how fast we respond, and the protection we extend to good-faith researchers.
Last updated: May 15, 2026
Reporting a vulnerability
Email support@norvetmsp.com with the subject line “Security Vulnerability Report”, or submit the contact form with the same tag. Include enough detail for us to reproduce the issue: affected URL or endpoint, a description of the vulnerability, reproduction steps, and (if relevant) a proof of concept. We accept reports in English.
This policy is also published in machine-readable form at /.well-known/security.txt (RFC 9116).
Scope
In scope:
norvetmsp.comand its subdomains- Norvet-operated web applications and APIs hosted on those domains
Out of scope (please do not test these):
- Third-party services and platforms Norvet uses or resells (carriers, data-center partners, SaaS vendors) — report those to the vendor directly
- Customer-owned environments Norvet manages under contract
- Findings that require physical access, social engineering of Norvet staff or customers, or denial-of-service / volumetric testing
- Reports from automated scanners with no demonstrated, exploitable impact (missing headers, version banners, etc.) unless chained into a concrete vulnerability
Our commitments
- Acknowledge your report within 3 business days.
- Triage and validate within 10 business days, with a severity assessment and an expected remediation window.
- Remediate on a severity-driven timeline — critical issues are prioritized for the fastest practical fix; lower-severity issues are scheduled into the normal release cycle.
- Keep you informed of progress and confirm when the issue is resolved.
- Credit you in our acknowledgments if you wish, once the issue is fixed.
Safe harbor
Norvet MSP will not pursue or support legal action against security researchers who, in good faith:
- Make a reasonable effort to follow this policy and stay within the stated scope;
- Avoid privacy violations, data destruction, service degradation, and access to or exfiltration of data beyond the minimum needed to demonstrate the vulnerability;
- Do not publicly disclose the issue before we have had a reasonable opportunity to remediate it (we will agree a coordinated disclosure timeline with you);
- Stop testing and notify us immediately if they encounter sensitive data (personally identifiable information, credentials, cardholder data, protected health information).
We consider security research conducted consistent with this policy to be authorized, and we will work with you to understand and resolve the issue quickly. This safe harbor does not apply to testing that violates applicable law or that targets the out-of-scope systems listed above.
What we ask of you
- Give us a reasonable time to remediate before any public disclosure.
- Do not use the vulnerability beyond what is necessary to confirm it exists, and do not access, modify, or delete other users’ data.
- Do not run automated load, brute-force, or denial-of-service tests.
Recognition
We are happy to publicly thank researchers who have responsibly disclosed valid issues. Tell us in your report whether — and how — you would like to be credited. Norvet MSP does not currently operate a paid bug-bounty program; recognition is by acknowledgment.
Report a vulnerability
support@norvetmsp.com · Contact form · (833) 281-9898
Norvet MSP is a Service-Disabled Veteran-Owned Small Business · SAM.gov-registered federal vendor (UEI NQFVNDX9RAV1 · CAGE 9SV80).
Here to check your own security?
This page is for reporting a vulnerability in our systems. If you run a small business and want to see where your own security stands, our free 10-question assessment gives you a grade and plain-language next steps in about two minutes. No login required.
Take the free security assessment