Support · Disclosure
Break it. Tell us. Stay protected.
A flaw you found is a flaw an adversary may already hold. We practice coordinated disclosure, we answer researchers first, and good faith is met with a safe harbor — not lawyers.
01 / THE PROCEDURE
Follow the procedure exactly.
-
Write to security@qeryx.com
The canonical channel, published in our security.txt. Security reports take priority over every other inbox.
-
Include what makes it reproducible
Affected surface, steps to reproduce, observed versus expected behavior, and impact as you understand it. A proof-of-concept is welcome; working exploitation of other people's data is not.
-
Coordinate the disclosure
We confirm receipt, keep you in the loop through the fix, and agree the publication timeline with you. Fixes and their credits land in the changelog.
02 / THE SAFE HARBOR
Read the safe harbor before you test.
Research conducted in good faith — testing against your own accounts and data, no service disruption, no access to other people's content — will not be met with legal action. The safe-harbor language lives with the Terms of Service; the program's scope and terms live at bug bounty.
03 / BEFORE YOU SEND
Answer three questions before you send.
Is there a bounty?
The program page at /security/bug-bounty states what is paid and for what — the terms live there, in one place, so this page can never drift from them.
What counts as in scope?
The clients, the relay, the crypto — anything whose failure breaks a promise this site makes. Scope details and exclusions live on the program page; when in doubt, send the report and say you were unsure.
Can I publish my findings?
Yes — coordinated. Agree the timeline with us so a fix ships before the write-up does. We will not sit on a report to avoid embarrassment; the changelog is public and versioned.