Security & disclosure
This page sets out how Nova Bank will and will not contact you, what protections are actually in place today, and the terms under which security researchers may test this site and report what they find.
Nova Bank will never ask you for a seed phrase, a private key, a password, a card number or a payment. There is no mechanism to accept any of them and no reason to want them. Anyone requesting one in Nova Bank's name is not Nova Bank. There is nothing to invest in, there is no token, and there is no presale.
1. How Nova Bank contacts you
- By email only, from Nova Bank's own domain, and only about the waitlist or the app.
- Account-confirmation and password-reset emails contain a six-digit code. Nova Bank will never telephone, text or direct-message you to ask for that code, or for your password. Anyone who does is attempting to take your account.
- Nova Bank operates no Telegram group, no Discord server, and no account that direct-messages people about early access. If you find one presenting itself as Nova Bank, please report it to security@novacard.us.
2. Measures currently in place
Stated plainly and without embellishment. Nova Bank is two people building a prototype, so what follows is a description of real measures, not a certification.
- All traffic is served over HTTPS with HSTS. HTTP is redirected and never served.
- A content security policy denies every source by default and blocks plugins outright. One third party is allowed: Cloudflare Turnstile, which protects the waitlist form from automated sign-ups, and which loads a script and a frame from challenges.cloudflare.com. Nothing else is permitted. This site loads no analytics, no advertising pixels and no third-party fonts, and sets no cookies of its own.
- Sign-in is an email address and a password. The password is handled by Nova Bank's authentication provider, which stores it hashed; Nova Bank never sees it and keeps no copy. Confirming a new account and resetting a password each use a six-digit code sent by email, which expires.
- Two-factor authentication with an authenticator app is supported.
- App sessions are stored in the iOS Keychain rather than in ordinary app storage.
- The app can be locked with a passcode and Face ID, and locks itself when you switch away from it.
- The app's simulated financial history is written to disk with iOS file protection enabled, so it is unreadable while the device is locked.
- Simulated financial data never leaves your device. There is no server-side copy to breach.
- Accounts held with Nova Bank's providers require two-factor authentication.
- Secrets are kept out of the source repository, and the repository is scanned for them.
What is expressly not claimed: that any of this is bank-grade, audited, penetration-tested or unbreakable. None of those statements would be true today, and this page will say so when one of them becomes true.
3. Reporting a vulnerability
If you find a security problem, please report it to Nova Bank before disclosing it elsewhere. Nova Bank will not threaten you and will not involve lawyers over a good-faith report.
Email security@novacard.us with enough detail to reproduce the issue. If you wish to encrypt your report, say so and a key will be arranged.
3.1 What you can expect in return
- An acknowledgement within 3 working days.
- An assessment and a plan within 10 working days.
- Credit on this page once the issue is resolved, if you would like it.
Nova Bank is unfunded and cannot offer a bounty. That is stated here directly rather than implying one exists.
3.2 What is asked of you
- Allow reasonable time for the issue to be fixed before publishing it.
- Do not access, alter or delete data that is not yours. If you reach someone else's data, stop, and report what you saw and nothing further.
- No denial of service, no spam, no social engineering of Nova Bank or its providers, and no physical attacks.
- Test against your own accounts and your own waitlist entries.
Testing that stays within those limits is considered authorised, and Nova Bank will bring no claim against you in respect of it.
3.3 Out of scope
- Findings from automated scanners without demonstrated impact.
- Missing headers or configuration weaknesses with no practical exploit path.
- Anything affecting only an unsupported or heavily modified browser.
- Reports that Nova Bank's financial data is not real. It is simulated deliberately — see What Nova is today.
4. If you believe your account has been taken
Email security@novacard.us immediately. Because a Nova Bank account holds no real money today, the worst case is limited — but Nova Bank still wants to know, and will close the account for you.
5. Contact
Security reports and account-compromise reports: security@novacard.us.
Anything else — questions, concerns, corrections, or a claim on this site that looks wrong: hello@novacard.us. Messages are read by the two people building Nova Bank, and answered plainly.
6. Changes to this page
This page is versioned and dated at the top, and is updated in the same session as the change that affects it.