Security
Vulnerability Disclosure
Status
This document has been drafted and is being finalised with counsel. The settled version will be published on this page before general availability, and account holders will be notified of the effective date. Until then, nothing on this page is a contractual term.
What it will cover
The Vulnerability Disclosure policy will set out how to report suspected vulnerabilities, the safe-harbour commitment to researchers acting in good faith, our acknowledgement and remediation timelines, and the boundaries (no accessing, modifying or exfiltrating data belonging to others; reasonable time to remediate before public disclosure).
Our practice today
- Suspected vulnerabilities can be reported today to hello@qanun.ai with steps to reproduce. Please do not access, modify or exfiltrate data belonging to others.
- We will acknowledge reports promptly and keep reporters informed while an issue is investigated and remediated.
- We will not pursue researchers who act in good faith, avoid privacy violations and service disruption, and allow reasonable time to remediate before disclosure.
Questions in the meantime: hello@qanun.ai
← Back to qanun.io