nomos system AG takes the security of its products seriously. If you have discovered a vulnerability in one of our products or services, we ask you to report it to us confidentially. We handle every report according to the principle of coordinated vulnerability disclosure.
Scope
This policy applies to all products and services of nomos system AG, in particular:
- nomos controller (hardware and firmware, all variants)
- nomos app for iOS and Android
- nomos configuration and administration interfaces
- nomos cloud services and remote access
- nomos Node-RED integration and other software published by us
How to report a vulnerability
Send your report to security@nomos-system.com. You can write to us in English, German or French.
To help us understand the issue quickly, please include:
- the affected product and version (controller firmware version, app version)
- a description of the vulnerability and its potential impact
- steps to reproduce, ideally with sample data or a proof of concept
- your name and whether you would like to be credited in a publication
Please do not report vulnerabilities through public channels such as social media or public issue trackers.
What you can expect from us
- We acknowledge receipt of your report within three business days.
- We assess the report and inform you of our evaluation and next steps within 14 days at the latest.
- We keep you informed about the progress of the fix.
- We coordinate the timing of any publication with you. Our goal is to fix confirmed vulnerabilities within 90 days. For complex cases this period may be extended in agreement with you.
- Once an update is available, we publish information about the fixed vulnerability in our release notes.
- If you wish, we credit you as the discoverer of the vulnerability.
We do not currently pay rewards for reports.
Rules for security researchers
We ask you to observe the following rules during your research:
- Only access systems that you own or that you have explicit permission to test. Do not test installations belonging to third parties.
- Do not read, modify or delete data that is not your own. If you unintentionally encounter third-party data while demonstrating a vulnerability, stop the test and let us know.
- Do not carry out attacks that impair the availability of our services or of our customers’ installations (for example denial of service).
- Refrain from social engineering, phishing and physical attacks.
- Give us reasonable time to fix the vulnerability before publishing any information about it.
Safe harbour
If you follow these rules and act in good faith, we will not take legal action against you and will consider your research authorised under applicable law. Should a third party take legal action against you, we will confirm that your actions were carried out within the scope of this policy.
Out of scope
We do not consider the following to be security vulnerabilities:
- reports from automated scanners without evidence of an actual impact
- missing security headers or best-practice recommendations without a concrete attack path
- vulnerabilities in third-party products that we merely integrate (for example devices of other manufacturers); please report these directly to the respective manufacturer
- access that requires physical access to the device or an administrator’s credentials, unless an additional flaw is involved
Machine-readable information
The point of contact is also published according to RFC 9116 at https://nomos-system.com/.well-known/security.txt.
Last updated: September 2026