Security
Vulnerability disclosure policy
How to report a security vulnerability in Jinkō or in infrastructure Nova operates, and what happens after you do.
If you have found a security vulnerability in Jinkō or in infrastructure Nova operates, report it to security@novainsilico.ai, also reachable as security@jinko.ai. Anyone may use this channel. No account, contract, or prior relationship is required.
We read the mailbox during CET business hours, five business days a week.
If it is urgent
Put URGENT in the subject line if your report claims any of:
- active exploitation
- unauthenticated access to client data
- access across organization boundaries
We acknowledge and triage those on the day they arrive during business hours, and on the next business day otherwise. The timelines below do not apply to them.
What counts is what your report claims, not what we confirm. A report that does not hold up rejoins the normal track, and we tell you why. One that does is an emergency whatever its base score.
Sending it encrypted
If you would rather not send an exploit, a proof of concept, or client data in plaintext, encrypt to our OpenPGP key at novainsilico.ai/.well-known/security-key.asc.
Fingerprint D00D 8A82 0F93 553D B355 A76B F8CD 0A5E 0DD8 59F9. It is a role key held by our security function, not by an individual.
Encryption is offered, never required. An unencrypted report is handled the same way, on the same clocks.
What we commit to
Acknowledgement within five business days, and a triage outcome within ten: accepted with a severity, duplicate, out of scope, or not a vulnerability.
Remediation on published timelines. An accepted report is handled exactly like a vulnerability we found ourselves:
| Severity | Remediation target |
|---|---|
| Critical | 7 days, with immediate mitigation or hardening within 24 to 48 hours |
| High | 30 days |
| Medium | 90 days |
| Low | 180 days |
Confirmed exploitation, or an issue exposed to the internet, is an emergency whatever its base score. Stricter terms agreed with a client take precedence. We re-test every fix before it is released.
Status until closure. We tell you when a fix is available and when we close the report. If we decide not to remediate, we tell you that, and why.
Confidentiality. Your report stays confidential until disclosure is coordinated with you. If it indicates an actual or suspected compromise, we open an incident alongside it.
Coordinated disclosure
Please allow 90 days from our acknowledgement before disclosing publicly. We will coordinate the timing and the wording with you. If you want credit, you get it.
Nova runs no bug bounty and pays no reward.
Safe harbor
We will not take legal action against you, and will not report you to law enforcement, for research carried out in good faith within these rules. We treat that research as authorized.
- Test only against accounts and data you own.
- Do not access, modify, retain, or exfiltrate anyone else's data.
- Do not degrade the service, and run no automated scanning, load testing, or active dynamic application security testing against production.
- Use no social engineering and no physical intrusion.
- Report promptly, and observe the disclosure window above.
Research outside those rules is outside the safe harbor.