No Code Jobs policy
Bug Bounty
Vulnerability Disclosure Policy
Last Updated: May 29, 2026
No Code Jobs appreciates good-faith security research that helps keep the Website, public job board, forms, feeds, and users safer.
We do not currently operate a paid bug bounty program unless we agree to a reward in writing before testing. This page describes how to report a vulnerability responsibly.
Reporting a Vulnerability
If you believe you found a security issue, email us at hello@nocodejobs.org with the subject line “Security report”.
Please include:
- A clear description of the issue.
- Steps to reproduce.
- The affected URL or endpoint.
- Screenshots, logs, or proof of concept details when helpful.
- Your contact information for follow-up.
Please do not include personal information belonging to another person unless it is necessary to explain the issue and you have handled it responsibly.
Safe Harbor
We will not pursue legal action against security researchers who act in good faith, follow this policy, avoid privacy harm, and stop testing when they discover a risk to users, data, or service availability.
This safe harbor does not apply to extortion, social engineering, data theft, spam, denial of service, destructive testing, or activity that violates the law.
Rules
You agree to:
- Test only against systems you are authorized to test.
- Use your own accounts, test data, or clearly labeled test submissions.
- Avoid accessing, modifying, deleting, downloading, or exfiltrating data that does not belong to you.
- Avoid disrupting the Website, public feeds, payment flows, forms, email systems, or third-party services.
- Stop immediately and report the issue if testing may expose personal information, payment information, resumes, application materials, or employer data.
- Give us a reasonable opportunity to investigate and remediate before public disclosure.
Out of Scope
The following are out of scope unless we specifically authorize them in writing:
- Denial of service or load testing.
- Social engineering, phishing, or physical attacks.
- Attacks against employers, applicants, partners, vendors, or third-party services.
- Spam or bulk form submissions.
- Automated scanner reports without a validated impact.
- Missing security headers or cookie flags without a practical exploit.
- Self-XSS or issues that require a user to paste code into the browser console.
- Reports about outdated software without a proof of exploitable impact.
- Public disclosure before we have reviewed the report.
Job Board and Agent Testing
If you are testing job application, job posting, contact, or agent-assisted submission flows, use obvious test data only. Do not submit real-person applications, fake employer listings, unsafe files, or personal information belonging to someone else.
AI browser agents and automation tools must follow the same rules. Agent testing must not bypass validation, rate limits, human-consent requirements, or abuse controls.
Contact
For security reports, contact:
Email: hello@nocodejobs.org