Security & Responsible Disclosure

Qntyx is a brand of Noel Innovations LLC. Last updated: 26 June 2026.

We take the security of our platform and our users seriously. If you believe you have found a security vulnerability in any Qntyx product or service, we want to hear from you — and we will work with you to verify, fix, and acknowledge it. We welcome good-faith security research.

Report a vulnerability

How to report

Email security@qntyx.io with:

Scope

In scope:

Out of scope

Safe harbor

We consider good-faith security research conducted under this policy to be authorized. We will not pursue or support legal action against researchers who:

Our commitment

RESPONSE COMMITMENTS

CRITICAL
Acknowledged within 24 hours. Fix deployed within 48 hours. Affected users notified.
HIGH
Acknowledged within 48 hours. Fix deployed within 7 days.
MEDIUM
Acknowledged within 5 business days. Fix within 30 days.
LOW
Acknowledged within 5 business days. Fix within 90 days.

BUG BOUNTY

We offer Hall of Fame recognition for all valid security disclosures. Paid bounties are coming — we will announce a formal program once our first security audit is complete.

Every researcher who responsibly discloses a valid vulnerability will be credited publicly (with their permission) and receive direct acknowledgment from our founding team.

HALL OF FAME

No disclosures yet. Be the first.

OUR SECURITY PRACTICES

⚛
Quantum Entropy
QuantumRand serves randomness from a NIST DRBG seeded on IBM Quantum hardware and reseeded daily; until the first hardware seed after a restart it runs on an operating-system seed and labels its output as a fallback (NIST SP 800-22 results at quantumrand.dev/nist-results). Some products draw from it and fall back to the operating system's random generator if it is unreachable; others use the operating system's generator directly.
🔐
Penetration Testing
Two internal penetration-test rounds run by our own team with Kali Linux (SQL injection, JWT attacks, TLS, MITM and more). These were not independent tests.
📋
Independent Audit
No third-party security audit has been done yet. When one is, we will publish the full results — including any findings and how we addressed them.
🔒
Encryption
Traffic to every endpoint uses TLS. Storage encryption at rest is provided by our hosting providers. Vault encrypts each secret with its own key (Fernet); the service can decrypt secrets, so it is not zero-knowledge.
🏗️
Certifications
Qntyx does not hold SOC 2 or any other certification, and no SOC 2 audit is underway. We will say so here when one starts.
📖
Open Source
Our source code is not public yet. We plan to publish the core entropy and audit-chain code for independent review, and will link it here when it is.