Security Policy
If you discover a security issue affecting Quadroplace, please report it privately. This page describes the preferred contact channels and the minimum rules for a responsible report.
Contact
Use either of the e-mail addresses below. Include the affected URL, the impact, clear reproduction steps, and if possible a proof-of-concept.
What we ask from researchers
- Do not publicly disclose the issue before we have had a reasonable chance to investigate and fix it.
- Do not access, modify, or delete data that does not belong to you.
- Do not degrade availability, run denial-of-service tests, or automate high-volume traffic against the live service.
- Use only the minimum amount of interaction needed to prove the issue exists.
What you can expect from us
- We aim to acknowledge valid reports within 5 business days.
- We will review the report and may contact you for clarification or validation details.
- There is currently no public bug bounty program.
Scope and good faith
If you act in good faith, avoid privacy violations and service disruption, and report the issue privately through the channels above, we will treat your report as a security disclosure intended to help improve the service.