Vulnerability disclosure
Report security concerns responsibly and confidentially.
QES values good-faith security research. This policy explains how to report a suspected vulnerability, what information helps us investigate and the conduct expected during testing.
How to report
Send the report directly to QES.
Email: contact@qesencryption.com
Subject line: QES Security Report
Please do not submit vulnerability details through social media, public issue trackers, reviews or other channels that may expose the report before it can be assessed.
What to include
Help us reproduce and assess the issue safely.
- A clear description of the suspected vulnerability and the affected QES product, page or release.
- The conditions required to observe the issue, including platform and version information where relevant.
- Minimal reproduction steps or a proof of concept that does not expose customer information.
- The security impact you believe could result from successful exploitation.
- Any temporary mitigation you identified during testing.
- Your preferred name or handle for acknowledgement, if applicable.
Remove passwords, personal information, customer content, secrets and unnecessary system data from screenshots, logs or supporting material.
Scope
Systems and software covered by this policy.
This policy applies to QES-controlled public web properties, supported QES client software and QES-operated services that are expressly presented as part of the QES product or corporate environment.
Not automatically authorised
- Third-party platforms, hosting providers, identity providers, payment services or other systems not operated by QES.
- Customer environments, customer accounts or data belonging to another person or organisation.
- Physical security testing, social engineering, phishing, pretexting or attempts to obtain credentials from QES personnel or customers.
- Testing that disrupts availability, degrades service, sends excessive traffic or alters production information.
Ask for written confirmation before testing any asset or technique where ownership or authorisation is unclear.
Research rules
Good-faith testing must minimise risk.
- Use only accounts and data you are authorised to access.
- Do not attempt to view, copy, modify, retain or transmit another party's information.
- Stop testing immediately if you encounter customer data, credentials, secrets or evidence of active compromise.
- Do not establish persistence, pivot to other systems or exploit a finding beyond what is necessary to demonstrate impact safely.
- Do not use denial-of-service techniques, destructive payloads, malware, automated high-volume scanning or resource-exhaustion testing.
- Do not publish the finding before QES has had a reasonable opportunity to investigate and coordinate remediation.
- Comply with applicable law and any additional written conditions agreed with QES.
Our response
What you can expect after a valid report.
QES aims to:
- Acknowledge a credible report within five business days.
- Complete an initial triage and provide a status update within ten business days where practical.
- Maintain a communication channel during investigation and remediation.
- Coordinate disclosure timing based on severity, affected customers, remediation readiness and public-interest considerations.
- Credit the reporter in an advisory where appropriate, requested and legally permitted.
Response targets are operational objectives rather than guaranteed service levels. Complex findings, incomplete reports or matters involving third parties may require additional time.
Safe harbour
Good-faith research conducted under this policy.
Where you make a reasonable, good-faith effort to follow this policy, QES will treat your activity as authorised for the limited purpose of identifying and reporting a security vulnerability and will not initiate legal action solely because of that compliant research.
This safe harbour does not authorise activity against third parties, customer systems, unlawful access, privacy violations, extortion, destructive conduct or actions outside the boundaries of this policy. It also does not bind any third party.
If you are uncertain whether planned testing is permitted, contact QES and obtain written authorisation before proceeding.
Coordinated disclosure
Protect users while the issue is being addressed.
QES supports coordinated disclosure. Publication timing should allow affected software or services to be assessed, remediation to be prepared and customers to receive practical guidance.
QES may publish a security advisory when doing so helps customers understand exposure, action required or the security status of supported releases. Sensitive exploit detail may be withheld where publication would create disproportionate risk.
Rewards
QES does not promise a financial reward, bounty or compensation for reports submitted under this policy unless a reward has been agreed in writing before the relevant work is performed.
Ready to report?
Use a clear subject line and minimal evidence.
Send a confidential report to contact@qesencryption.com and include the affected product, reproduction conditions and likely impact.