generated: '2026-08-01' method: searched probe: true source: https://nordlayer.com/.well-known/security.txt policy: [] contact: - mailto:support@nordlayer.com security_txt: url: https://nordlayer.com/.well-known/security.txt file: well-known/nord-security-nordlayer-security.txt http_status: 200 fields: canonical: https://nordlayer.com/.well-known/security.txt contact: mailto:support@nordlayer.com expires: '2026-12-31T00:00:00Z' preferred_languages: en gaps: - No `Policy:` field — the file gives a contact but points at no disclosure policy. - No `Encryption:`, `Acknowledgments:` or `Hiring:` fields. - >- Published only on the NordLayer product domain (and its api. host). nordsecurity.com, nordstellar.com, nordpass.com and nordvpn.com all return 404/403 for /.well-known/security.txt, so the corporate parent and the other four products have no RFC 9116 contact. bug_bounty: status: not-publicly-listed historical: true platform: HackerOne documented_by: - https://nordvpn.com/blog/nord-security-bug-bounty-launch/ - https://nordvpn.com/blog/bug-bounty-program-launch/ - https://nordvpn.com/blog/bug-bounty-results/ note: >- Nord Security ran a public HackerOne program from December 2019 (launched for NordVPN, extended in 2021 to NordPass and NordLocker and later NordLayer), with published payouts up to $50,000 for critical findings. As of this probe the `nordsecurity` handle no longer resolves on HackerOne — both the program page and the HackerOne GraphQL team lookup return not-found — so the program is either private/invitation-only or retired. Recorded as historical, not as a live public program. evidence: - source: https://nordlayer.com/.well-known/security.txt kind: security.txt http_status: 200 fetched: '2026-08-01' - source: https://api.nordlayer.com/.well-known/security.txt kind: security.txt http_status: 200 fetched: '2026-08-01' note: byte-identical duplicate served from the API host - source: https://hackerone.com/nordsecurity kind: bug-bounty-probe http_status: 404 fetched: '2026-08-01' - source: 'https://hackerone.com/graphql {team(handle:"nordsecurity")}' kind: bug-bounty-probe http_status: 200 result: 'NOT_FOUND — "Team does not exist" (control handle "security" resolves)' fetched: '2026-08-01'