Security

Responsible disclosure

We build security tools, so we take our own seriously. If you find a vulnerability in Queldrex, we want to hear from you, and we won't pursue action against good-faith research.

How to report

Email hello@queldrex.com with steps to reproduce, impact, and any proof-of-concept. We aim to acknowledge within 3 business days and to keep you updated as we investigate and fix.

Safe harbor

We will not initiate legal action against you for security research conducted in good faith that: respects user privacy, avoids degrading our service, does not access or modify data that isn't yours, and gives us reasonable time to remediate before public disclosure. If in doubt, ask us first.

In scope

  • queldrex.com and its subdomains
  • The Trust Layer API (/api/trust/*) and the verification engine
  • The Trust Receipt signing and verification flow

Out of scope

  • Denial-of-service / volumetric attacks, and automated scanning that degrades service
  • Social engineering of our team or users
  • Reports from automated tools without a demonstrated, exploitable impact
  • Findings in third-party services we depend on (report those to the vendor)

No bounty yet

We don't run a paid bug-bounty program at this stage, but we credit researchers (with your permission) and will prioritize a fair reward program as we grow. Your good-faith report is genuinely valued.

Machine-readable policy: /.well-known/security.txt (RFC 9116).