
I suggest improving the response time for submitted security reports. It would be helpful if researchers could receive responses or status updates on their reports in a timely manner, especially when reports have already been submitted and are awaiting review.
This would make the reporting experience smoother and provide better communication between the security team and researchers.

I also noticed that the vulnerabilities I reported to you have now been fixed, but I still haven’t received any response. Why is that?

@Ayman Amer thanks for flagging this. We have experienced a significant increase in the volume of low-quality ineligible AI-generated reports which have flooded our security reports mailbox. We are working on an improved system for submitting reports which relies on registration by security researchers, linking submitted reports to researcher profiles, and prioritizing researchers with a history of high quality reports and positive signals like public profiles/reputation.
I will lookup any reports submitted by you (from your email) and get back to you by the end of this week.

Thank you, @Amit . I submitted four reports using the same email address I’m contacting you from. I received a response on only one report, while the other three were not responded to, although I noticed that they were fixed some time after I reported them. These were high-quality reports, so I’d appreciate it if you could look into them as well.

hi @Amit , It has been more than a week, and I still haven’t received any response, as you mentioned would be the case.

@Ayman Amer Thanks for your patience and for helping improve Nolt’s security. We’ve reviewed your remaining reports and sent the outcomes by email.