Skip to content

Trust Center

Vulnerability disclosure policy

How to report security issues in Qtangl products and infrastructure responsibly.

Scope

  • qtangl.com and www.qtangl.com (marketing and dashboard web applications)
  • api.qtangl.com (Qtangl API and scanner endpoints)
  • Authenticated tenant dashboard flows hosted on Qtangl infrastructure

Out of scope

  • Social engineering, physical security, or third-party SaaS not operated by Qtangl
  • Denial-of-service attacks against production services
  • Issues in customer-controlled scan targets or tenant-uploaded content
  • Reports without sufficient reproduction steps or impact assessment

Contact

Email charley@qtangl.com with subject line [SECURITY]. Include reproduction steps, affected URLs or endpoints, impact assessment, and your preferred contact method.

Canonical machine-readable policy: /.well-known/security.txt

Safe harbor

Qtangl supports good-faith security research that follows this policy. We will not pursue legal action under the Computer Fraud and Abuse Act or similar laws for research conducted in compliance with these guidelines, provided you do not exfiltrate customer data, degrade service availability, or access accounts that are not your own.

Response SLAs

  • Acknowledgement: within 2 business days
  • Critical remediation target: 30 days
  • High remediation target: 60 days
  • Medium remediation target: 90 days

Coordinated disclosure

We ask researchers to allow up to 90 days after acknowledgement before public disclosure, unless we agree on a different timeline. Extensions are available by mutual agreement when remediation requires additional time.

Recognition and bounty

With your permission, valid in-scope reports may be listed on /trust/security. Qtangl does not operate a paid bug bounty program at this time.

← Trust Center