Responsible Disclosure

Vulnerability
Disclosure Policy

Last updated: August 2026

QAVRIC welcomes responsible disclosure of security vulnerabilities. If you discover a security issue affecting QAVRIC systems, we want to know — and we commit to responding seriously and promptly.

How to Report

Send your disclosure to: security@qavric.com

Include as much detail as possible:

  • A description of the vulnerability
  • The affected system or URL
  • Steps to reproduce
  • Potential impact as you understand it
  • Your preferred contact method for follow-up

Our Commitments to You

  • We will acknowledge receipt within 48 hours.
  • We will provide a meaningful update within 7 days.
  • We will keep you informed of our remediation progress.
  • We will not take legal action against researchers who act in good faith and follow this policy.
  • We will credit you publicly if you wish — and only if you wish.

Scope

This policy applies to security vulnerabilities in:

  • qavric.com and any QAVRIC-operated subdomains
  • QAVRIC-published software tools and repositories
  • Any other system explicitly operated by QAVRIC

This policy does not cover third-party services used by QAVRIC. If you discover a vulnerability in a third-party service, please report it directly to that organization.

What We Ask of You

  • Act in good faith. Do not exploit the vulnerability beyond what is necessary to demonstrate it.
  • Do not access, modify, or delete data that does not belong to you.
  • Do not perform denial-of-service attacks.
  • Do not perform social engineering against QAVRIC personnel.
  • Do not disclose the vulnerability publicly before we have had a reasonable opportunity to remediate.
  • Contact us before public disclosure. We will work with you on coordinated release.

QAVRIC Research Disclosures

When QAVRIC discovers vulnerabilities in third-party systems through our own research, we follow a structured responsible disclosure process:

  • We notify the affected vendor privately before any public disclosure.
  • We provide a clear, reproducible description of the vulnerability.
  • We allow a minimum of 90 days for remediation before any public disclosure.
  • We coordinate timing with the vendor where possible.
  • We publish only what is necessary to communicate the risk — no gratuitous detail.

security.txt

Our security.txt is published at the standard location. We treat it as a real operational endpoint, not decoration.

Report a Vulnerabilitysecurity@qavric.com