Platform Security & Vulnerability Policy
Notexia prioritizes student data safety and academic research confidentiality. We implement strict defense-in-depth security standards to protect users against unauthorized access, data leaks, and cyber threats.
1. Core Security Controls
MongoDB clusters and backups are encrypted with AES-256 standards. User passwords are salted and hashed using bcrypt (10 rounds).
Strict HTTPS enforcement with TLS 1.3 encryption across all website routes, websocket instances, and API endpoints.
Cloudflare edge firewall filtering, automated IP rate limits, and brute-force mitigation on authentication routes.
Real-time error logging, anomalous traffic detection, and security audit telemetry.
2. Responsible Vulnerability Disclosure
We welcome ethical security researchers to test and report vulnerabilities responsibly. If you discover a security vulnerability on Notexia, please email us directly before public disclosure.
- Email details to: [email protected]
- Provide reproduction steps, proof-of-concept, and affected endpoint URLs.
- Do not access or alter user data without permission during security testing.
Report a Security Emergency?
Contact Security Engineering immediately at [email protected].