INVITE ONLY
OBSERVATORY

Support · Disclosure

Break it. Tell us. Stay protected.

A flaw you found is a flaw an adversary may already hold. We practice coordinated disclosure, we answer researchers first, and good faith is met with a safe harbor — not lawyers.

Follow the procedure exactly.

  1. Write to security@qeryx.com

    The canonical channel, published in our security.txt. Security reports take priority over every other inbox.

  2. Include what makes it reproducible

    Affected surface, steps to reproduce, observed versus expected behavior, and impact as you understand it. A proof-of-concept is welcome; working exploitation of other people's data is not.

  3. Coordinate the disclosure

    We confirm receipt, keep you in the loop through the fix, and agree the publication timeline with you. Fixes and their credits land in the changelog.

Read the safe harbor before you test.

Research conducted in good faith — testing against your own accounts and data, no service disruption, no access to other people's content — will not be met with legal action. The safe-harbor language lives with the Terms of Service; the program's scope and terms live at bug bounty.

Answer three questions before you send.

Is there a bounty?

The program page at /security/bug-bounty states what is paid and for what — the terms live there, in one place, so this page can never drift from them.

What counts as in scope?

The clients, the relay, the crypto — anything whose failure breaks a promise this site makes. Scope details and exclusions live on the program page; when in doubt, send the report and say you were unsure.

Can I publish my findings?

Yes — coordinated. Agree the timeline with us so a fix ships before the write-up does. We will not sit on a report to avoid embarrassment; the changelog is public and versioned.