Security & Responsible Disclosure

Qntyx is a brand of Noel Innovations LLC. Last updated: 26 June 2026.

We take the security of our platform and our users seriously. If you believe you have found a security vulnerability in any Qntyx product or service, we want to hear from you — and we will work with you to verify, fix, and acknowledge it. We welcome good-faith security research.

Report a vulnerability

How to report

Email security@qntyx.io with:

Scope

In scope:

Out of scope

Safe harbor

We consider good-faith security research conducted under this policy to be authorized. We will not pursue or support legal action against researchers who:

Our commitment

RESPONSE COMMITMENTS

CRITICAL
Acknowledged within 24 hours. Fix deployed within 48 hours. Affected users notified.
HIGH
Acknowledged within 48 hours. Fix deployed within 7 days.
MEDIUM
Acknowledged within 5 business days. Fix within 30 days.
LOW
Acknowledged within 5 business days. Fix within 90 days.

BUG BOUNTY

We offer Hall of Fame recognition for all valid security disclosures. Paid bounties are coming — we will announce a formal program once our first security audit is complete.

Every researcher who responsibly discloses a valid vulnerability will be credited publicly (with their permission) and receive direct acknowledgment from our founding team.

HALL OF FAME

No disclosures yet. Be the first.

OUR SECURITY PRACTICES

Quantum Entropy
All cryptographic operations are seeded with entropy from IBM Quantum hardware via QuantumRand. NIST SP 800-22 verified. Results published at quantumrand.dev/nist-results.
🔐
Penetration Testing
Two independent penetration test rounds completed prior to launch using Kali Linux. All findings remediated. SQL injection, JWT attacks, TLS, MITM, and more tested.
📋
Independent Audit
Third-party security audit scheduled for Q4 2026. We will publish the full results — including any findings and how we addressed them.
🔒
Encryption
All data encrypted at rest and in transit. TLS 1.2+ enforced on all endpoints. Secrets stored with unique per-secret quantum-derived encryption keys.
🏗️
SOC 2 Type II
SOC 2 Type II audit process beginning Q3 2026. Controls framework in place. Certification expected Q1 2027.
📖
Open Source
Core cryptographic primitives — open source release coming soon at github.com/qntyx. Independent verification of our entropy and audit chain implementations.