Trust Center
Vulnerability disclosure policy
How to report security issues in Qtangl products and infrastructure responsibly.
Scope
- qtangl.com and www.qtangl.com (marketing and dashboard web applications)
- api.qtangl.com (Qtangl API and scanner endpoints)
- Authenticated tenant dashboard flows hosted on Qtangl infrastructure
Out of scope
- Social engineering, physical security, or third-party SaaS not operated by Qtangl
- Denial-of-service attacks against production services
- Issues in customer-controlled scan targets or tenant-uploaded content
- Reports without sufficient reproduction steps or impact assessment
Contact
Email charley@qtangl.com with subject line [SECURITY]. Include reproduction steps, affected URLs or endpoints, impact assessment, and your preferred contact method.
Canonical machine-readable policy: /.well-known/security.txt
Safe harbor
Qtangl supports good-faith security research that follows this policy. We will not pursue legal action under the Computer Fraud and Abuse Act or similar laws for research conducted in compliance with these guidelines, provided you do not exfiltrate customer data, degrade service availability, or access accounts that are not your own.
Response SLAs
- Acknowledgement: within 2 business days
- Critical remediation target: 30 days
- High remediation target: 60 days
- Medium remediation target: 90 days
Coordinated disclosure
We ask researchers to allow up to 90 days after acknowledgement before public disclosure, unless we agree on a different timeline. Extensions are available by mutual agreement when remediation requires additional time.
Recognition and bounty
With your permission, valid in-scope reports may be listed on /trust/security. Qtangl does not operate a paid bug bounty program at this time.