Security
How to reach us about a security issue, and what we are prepared to say publicly. We do not publish our controls, our architecture or our operational detail.
What we are prepared to say
Game outcomes are decided by us, not by anything running on a player device, and a result cannot be altered after the fact. No person at Nordon can intervene in a round in progress, change a result or give one player different odds from another.
Access to our systems is limited to the people who need it, changes reaching production are reviewed and recorded, and partner data and credentials are kept separate per partner and per environment. Our public website and any demo on it run apart from anything that handles real money.
Detail beyond this, including our architecture, our controls and our assessment evidence, is shared with partners and independent assessors under agreement. Publishing it would help nobody except an attacker.
Reporting a vulnerability
If you believe you have found a vulnerability in this website or in a Nordon demo, write to the address below with enough detail for us to reproduce it, and give us a reasonable period to respond before you discuss it publicly. We will confirm that we received it, keep you posted, and credit you if you would like to be named.
Please do not run scanning that degrades the service for others, do not try to reach data that is not yours, and do not use social engineering against our people or our partners.