Vulnerability disclosure

Vulnerability disclosure

We welcome responsible reports of security issues affecting QData Projects operated services.

Report a vulnerability

Use the security contact channel. Include reproduction steps, impact assessment and affected URLs or components.

Security contact · security.txt

Scope

QData Projects SaaS at projects.qdata.cloud and associated operated infrastructure under QData control for this product. Out of scope: third-party services not operated for QData Projects, social engineering, physical attacks and denial-of-service tests without prior agreement.

Safe harbor

We will not pursue legal action for good-faith research that follows this policy, avoids privacy violations and data destruction, and gives us reasonable time to remediate before public disclosure.

Coordinated disclosure

We prefer coordinated disclosure. We will acknowledge receipt and work toward remediation. Public advisories are published when appropriate — see Trust Center updates.