Security
Found a vulnerability? Tell us.
We'd genuinely rather hear from you than not. Every report gets a response from a person, and we won't pursue legal action against researchers acting in good faith under this policy.
How to reach us
Two routes, and neither is preferred. Use whichever you are comfortable with.
Or use this form
For anyone who would rather not use email.
What you can expect from us
- 01
Acknowledgement within two working days. From a person, not an autoresponder.
- 02
An honest assessment. We'll tell you whether we consider it a vulnerability and why.
- 03
Updates as we fix it. You won't have to chase us.
- 04
Credit if you want it. Named in our disclosure record, unless you'd rather stay anonymous.
- 05
No legal action against researchers acting in good faith under this policy.
Scope
In scope
- This website
- The Quarkino Core API on any instance you have permission to test
- Quarkino Admin on any instance you have permission to test
Out of scope
- Any client's production system you do not have written permission to test
- Denial of service
- Social engineering of our team or our clients
- Physical attacks
- Reports from automated scanners with no demonstrated impact
- Missing security headers with no demonstrated exploit
While you're testing
- Don't access, modify, or delete data that isn't yours.
- Don't degrade service for anyone else.
- Don't publish before we've had a reasonable chance to fix it — talk to us about timing.
- If you accidentally access personal data, stop, and tell us what you saw.
None of this is meant to sound defensive. It is the shortest way to say: test the thing, not the people, and tell us before you tell everyone.