Security & Responsible Disclosure
We take the security of our platform and our users seriously. If you believe you have found a security vulnerability in any Qntyx product or service, we want to hear from you — and we will work with you to verify, fix, and acknowledge it. We welcome good-faith security research.
How to report
Email security@qntyx.io with:
- A clear description of the issue and its potential impact
- Step-by-step instructions to reproduce it (proof-of-concept, requests, screenshots)
- The affected URL, product, or endpoint
- How we can reach you for follow-up
Scope
In scope:
- qntyx.io and its subdomains (e.g. app, docs, status, and product APIs)
- Qntyx product backends, dashboards, and APIs operated by Noel Innovations LLC
Out of scope
- Denial-of-service (DoS/DDoS), volumetric, or resource-exhaustion attacks
- Social engineering, phishing, or physical attacks against staff or facilities
- Spam, or reports of missing email hardening (SPF/DKIM/DMARC) without a demonstrated impact
- Automated scanner output or theoretical issues without a working proof-of-concept
- Vulnerabilities in third-party platforms we rely on (Cloudflare, Vercel, Railway, Supabase, Stripe) — please report those to the respective vendor
Safe harbor
We consider good-faith security research conducted under this policy to be authorized. We will not pursue or support legal action against researchers who:
- Make a good-faith effort to avoid privacy violations, data destruction, and service degradation
- Only interact with accounts they own or have explicit permission to test
- Do not exfiltrate, modify, or retain data beyond the minimum needed to demonstrate the issue
- Give us a reasonable opportunity to remediate before public disclosure
Our commitment
- We will acknowledge your report within 5 business days
- We will keep you updated as we investigate and remediate
- We will credit researchers who responsibly disclose, if they wish
- We do not currently offer a monetary bug-bounty program, but we deeply appreciate your help
RESPONSE COMMITMENTS
BUG BOUNTY
We offer Hall of Fame recognition for all valid security disclosures. Paid bounties are coming — we will announce a formal program once our first security audit is complete.
Every researcher who responsibly discloses a valid vulnerability will be credited publicly (with their permission) and receive direct acknowledgment from our founding team.
No disclosures yet. Be the first.