Security // Responsible disclosure
Report a suspected security issue.
Email security@quantumcyberops.com with the affected asset, concise reproduction steps, and potential impact. Request a protected channel before sending sensitive evidence.
Good-faith research
Avoid privacy violations, persistence, social engineering, physical testing, denial of service, data destruction, automated high-volume scanning, or access beyond what is necessary to demonstrate the issue. Stop if you encounter personal, confidential, or client information.
Response targets
- Initial acknowledgement target: two business days.
- Initial triage target: five business days.
- Remediation and disclosure timing depend on severity, affected parties, and operational risk.
Not a bug bounty
This policy does not create a promise of payment. Rewards, public recognition, or disclosure coordination are considered at QuantumCyberOps’ discretion and must be agreed in writing.
Safe harbor
We will not pursue action for accidental, good-faith research that follows this policy, stays within our owned systems, avoids harm, and is reported promptly. This statement does not authorize testing of client, supplier, or third-party systems.
Report securely