Vulnerability disclosure
We welcome responsible reports of security issues affecting QData Projects operated services.
Report a vulnerability
Use the security contact channel. Include reproduction steps, impact assessment and affected URLs or components.
Security contact · security.txt
Scope
QData Projects SaaS at projects.qdata.cloud and associated operated infrastructure under QData control for this product. Out of scope: third-party services not operated for QData Projects, social engineering, physical attacks and denial-of-service tests without prior agreement.
Safe harbor
We will not pursue legal action for good-faith research that follows this policy, avoids privacy violations and data destruction, and gives us reasonable time to remediate before public disclosure.
Coordinated disclosure
We prefer coordinated disclosure. We will acknowledge receipt and work toward remediation. Public advisories are published when appropriate — see Trust Center updates.