09 Security · Bug Bounty
Break it before they do.
Good-faith research on QERYX is authorized and protected. Here is the scope, the process, and the safe harbor in writing.
01Scope — aim at the protocol first
Aim at the protocol before the app.
The highest-value findings are protocol-level: anything that lets the relay read content, link blinded identifiers across windows, forge a delivery proof, or survive a Q-Ratchet rotation it should not.
In scope
The iOS and Android clients, crypto-core, the relay API and WebSocket surface, QLEAP, key transparency (KTS-Quorum), sealed sender, and this website. Your own accounts and devices only.
Out of scope
Denial of service against production, spam or social engineering of QERYX staff or users, physical attacks, findings requiring a fully compromised endpoint (a compromised endpoint reads what its user reads — that is stated in the threat model), and third-party infrastructure we do not operate.
Rewards
Rewards are assessed per report by severity and reproducibility. Published reward bands are being finalized; this page will carry the numbers when they are set, and not before.
02Report — acknowledged within 72 hours
Report it once, to the people who fix it.
Write to security@qeryx.com with reproduction steps. We acknowledge within 72 hours, keep you updated through the fix, and credit you in the disclosure unless you prefer otherwise. Coordinated disclosure window: 90 days, extendable by agreement when a fix genuinely needs it.
curl -s https://qeryx.com/.well-known/security.txt
Encrypted contact keys — pending key ceremony
The PGP and ML-DSA-87 contact keys publish here after the offline key ceremony completes. Until the fingerprints are real, none are shown — a contact key you cannot verify is worse than none.
03Safe harbor — in writing, before you start
Read the harbor clause before you start.
Security research on QERYX conducted in good faith is authorized. If you make a good-faith effort to follow this policy — test only against your own accounts, avoid degrading service for others, do not access or retain another person’s data, and report promptly — QERYX Inc. will not initiate legal action against you for that research and will not refer it for prosecution. Where a third party raises a claim, we will state on record that your research was authorized. The canonical clause lives at /security#safe-harbor, the URL our security.txt names as Policy.
04The record — the questions we get asked hardest
The hard questions.
Will you actually credit findings that embarrass you?
Yes. The transparency page lists deviations we found in our own posture; a researcher’s finding gets the same treatment. The disclosure names the finding, the fix, and the reporter.
Can I publish my research after the fix?
Yes — after the coordinated window or the fix shipping, whichever comes first. We ask for coordination, never for silence.