logo

Security & Abuse Reporting

Last Updated: September 17, 2026

Notessa welcomes reports of security vulnerabilities and of abusive content. This page explains how to reach us and what to expect.

HOW TO REPORT

Email security@notessa.ai. This inbox is monitored, and it is the correct address for every report described on this page. If you believe the matter is sensitive, say so in the subject line and we will arrange a secure channel before you send details.

REPORTING A SECURITY VULNERABILITY

If you believe you have found a vulnerability in Notessa, please include as much of the following as you can:

  • A description of the issue and why you believe it is a security problem.
  • The steps needed to reproduce it, including any URL, account or request involved.
  • What an attacker could obtain or change by exploiting it.
  • Any logs, screenshots or proof-of-concept code that help us confirm it.

We ask that you give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly.

REPORTING ABUSE

Notessa generates documents on behalf of its customers, and serves them from the domain notessausercontent.com. Content on that domain is produced within a customer's private workspace and is not published or indexed, but if you have received a link to a page there and believe it is being used for phishing, malware distribution, or any other abusive purpose, report it to the same address.

When reporting abuse, please include:

  • The full URL of the page concerned.
  • How you came to receive the link.
  • What about it appears abusive.

We will investigate, remove content that violates our terms, and act against the originating account where appropriate.

WHAT TO EXPECT

  • We acknowledge reports within three business days.
  • We aim to give an assessment, including whether we have been able to reproduce the issue, within ten business days.
  • We will tell you when the matter is resolved. If we decide a report does not describe a problem we intend to act on, we will say so and explain why.
  • We do not currently run a paid bug bounty programme.

GOOD-FAITH RESEARCH

We will not pursue or support legal action against anyone who reports a vulnerability to us in good faith, provided that the research:

  • stays within accounts and data you own or have explicit permission to test;
  • does not degrade, disrupt or interrupt the service for others;
  • does not access, modify, destroy or retain another customer's data, and stops at the point that access is demonstrated;
  • does not use social engineering, physical intrusion, or attacks against our staff or suppliers; and
  • gives us a reasonable period to remediate before any public disclosure.

If you are unsure whether something you intend to do falls within this, ask us first at security@notessa.ai.

OTHER ENQUIRIES

For questions about privacy or the handling of personal data, see our Privacy Policy. For customer support that is not a security or abuse matter, please use the contact details on our home page.