INVITE ONLY
OBSERVATORY

09 Security · Bug Bounty

Break it before they do.

Good-faith research on QERYX is authorized and protected. Here is the scope, the process, and the safe harbor in writing.

Aim at the protocol before the app.

The highest-value findings are protocol-level: anything that lets the relay read content, link blinded identifiers across windows, forge a delivery proof, or survive a Q-Ratchet rotation it should not.

In scope

The iOS and Android clients, crypto-core, the relay API and WebSocket surface, QLEAP, key transparency (KTS-Quorum), sealed sender, and this website. Your own accounts and devices only.

Denial of service against production, spam or social engineering of QERYX staff or users, physical attacks, findings requiring a fully compromised endpoint (a compromised endpoint reads what its user reads — that is stated in the threat model), and third-party infrastructure we do not operate.

Rewards are assessed per report by severity and reproducibility. Published reward bands are being finalized; this page will carry the numbers when they are set, and not before.

Report it once, to the people who fix it.

Write to security@qeryx.com with reproduction steps. We acknowledge within 72 hours, keep you updated through the fix, and credit you in the disclosure unless you prefer otherwise. Coordinated disclosure window: 90 days, extendable by agreement when a fix genuinely needs it.

the machine-readable policy
curl -s https://qeryx.com/.well-known/security.txt

Encrypted contact keys — pending key ceremony

The PGP and ML-DSA-87 contact keys publish here after the offline key ceremony completes. Until the fingerprints are real, none are shown — a contact key you cannot verify is worse than none.

Read the harbor clause before you start.

Security research on QERYX conducted in good faith is authorized. If you make a good-faith effort to follow this policy — test only against your own accounts, avoid degrading service for others, do not access or retain another person’s data, and report promptly — QERYX Inc. will not initiate legal action against you for that research and will not refer it for prosecution. Where a third party raises a claim, we will state on record that your research was authorized. The canonical clause lives at /security#safe-harbor, the URL our security.txt names as Policy.

The hard questions.

Yes. The transparency page lists deviations we found in our own posture; a researcher’s finding gets the same treatment. The disclosure names the finding, the fix, and the reporter.

Yes — after the coordinated window or the fix shipping, whichever comes first. We ask for coordination, never for silence.