NicholicIndependent

Security

Security and responsible disclosure

If you have found something, the address is below and it is read by a person. The good-faith promise and the response targets cover everything Nicholic runs, including TruXSocial. Nothing here is claimed that is not implemented and running.

Good-faith research

Reporting a vulnerability in good faith will not be treated as an attack. Nicholic will not pursue legal action against anyone who finds a problem, reports it privately, and gives a reasonable chance to fix it before saying anything publicly.

Good faith means not accessing more data than needed to demonstrate the issue, not degrading the service for anyone else, and not holding a finding for leverage.

What to expect

These are targets, not guarantees, and the difference is deliberate. One person cannot staff a service level, and a published guarantee that gets missed is exactly the failure this site tells people to watch for. In practice these are usually beaten.

Response targets
StageTarget
Acknowledgement that the report was received and readThree working days
A first substantive assessmentFourteen days
Public write-up after a confirmed incidentSeven days from confirmation

If a target is missed, it gets reported as missed rather than quietly removed from this page.

What is not claimed

  • There is no paid bug bounty. Reports are wanted and credited, but there is no money to pay for them, and saying so is better than leaving it ambiguous.
  • There has been no independent security audit and no certification. Neither is affordable yet.
  • There is no guaranteed fix time. A fix takes as long as it takes, and the assessment will say what is known.
  • There is no 24-hour coverage. One person, one time zone.

What actually protects this website today

Tier 2 — general

This site is static files. There is no server executing code, no database, no user accounts and no login — which removes most of the surface a site like this would otherwise have.

Each of the following was checked on the deployed site, not assumed. Served over HTTPS only, with HSTS. A content security policy that blocks third-party script origins, plus nosniff, a deny-framing header and a permissions policy that switches off device access the site never needs. No analytics, no advertising, and no scripts loaded from another host. Fonts are downloaded at build time and served from this origin, so loading a page fetches nothing from another host.

What is deliberately not described here: where anything is hosted, how it is deployed, and what protects the accounts behind it. The reasoning is on the transparency page.

After an incident

If a security or privacy incident affects anyone, it gets published — including incidents nobody outside would ever have discovered. Reports go in the incident log, with what happened, when it was found, what was affected, and what changed as a result.

If this site itself is unreachable during an incident, notice goes out through a second channel. [FOUNDER TO CONFIRM: name the out-of-band channel] Keeping one external account alive purely for this is the only reason to have one.