Security & Disclosure
Machine-readable policy: /.well-known/security.txt ยท Encryption keys: /pgp
Reporting
Email camden.carter@quietpointsecurity.com or use the form below. Encrypt technical detail and PoC with our disclosure key. Include the affected asset, impact, and clear reproduction steps.
Our commitment
- We acknowledge reports within 3 business days and give a triage decision within 10.
- We keep you updated on remediation and coordinate disclosure timing with you.
- We do not pursue legal action for good-faith research that respects the scope below.
Safe harbor & scope
Good-faith testing that avoids privacy violations, data destruction, service degradation, and social engineering of our staff or clients is authorized. Do not access, modify, or exfiltrate data that isn't yours. Stop and report on encountering user data. High-volume automated scanning of production is out of scope.
Out of scope
- Automated-tool output without a demonstrated, exploitable impact
- Missing best-practice headers on non-sensitive endpoints
- Denial-of-service, rate-limiting and volumetric issues
- Third-party services we do not operate