Skip to content

Quiet Point Security

Security & Disclosure

Last updated:

Security & Disclosure

Machine-readable policy: /.well-known/security.txt ยท Encryption keys: /pgp

Reporting

Email camden.carter@quietpointsecurity.com or use the form below. Encrypt technical detail and PoC with our disclosure key. Include the affected asset, impact, and clear reproduction steps.

Our commitment

  • We acknowledge reports within 3 business days and give a triage decision within 10.
  • We keep you updated on remediation and coordinate disclosure timing with you.
  • We do not pursue legal action for good-faith research that respects the scope below.

Safe harbor & scope

Good-faith testing that avoids privacy violations, data destruction, service degradation, and social engineering of our staff or clients is authorized. Do not access, modify, or exfiltrate data that isn't yours. Stop and report on encountering user data. High-volume automated scanning of production is out of scope.

Out of scope

  • Automated-tool output without a demonstrated, exploitable impact
  • Missing best-practice headers on non-sensitive endpoints
  • Denial-of-service, rate-limiting and volumetric issues
  • Third-party services we do not operate