visit us at

nomos system AG takes the security of its products seriously. If you have discovered a vulnerability in one of our products or services, we ask you to report it to us confidentially. We handle every report according to the principle of coordinated vulnerability disclosure.

Scope

This policy applies to all products and services of nomos system AG, in particular:

How to report a vulnerability

Send your report to security@nomos-system.com. You can write to us in English, German or French.

To help us understand the issue quickly, please include:

Please do not report vulnerabilities through public channels such as social media or public issue trackers.

What you can expect from us

We do not currently pay rewards for reports.

Rules for security researchers

We ask you to observe the following rules during your research:

Safe harbour

If you follow these rules and act in good faith, we will not take legal action against you and will consider your research authorised under applicable law. Should a third party take legal action against you, we will confirm that your actions were carried out within the scope of this policy.

Out of scope

We do not consider the following to be security vulnerabilities:

Machine-readable information

The point of contact is also published according to RFC 9116 at https://nomos-system.com/.well-known/security.txt.

Last updated: September 2026