Vulnerability
Disclosure Policy
Last updated: August 2026
QAVRIC welcomes responsible disclosure of security vulnerabilities. If you discover a security issue affecting QAVRIC systems, we want to know — and we commit to responding seriously and promptly.
How to Report
Send your disclosure to: security@qavric.com
Include as much detail as possible:
- A description of the vulnerability
- The affected system or URL
- Steps to reproduce
- Potential impact as you understand it
- Your preferred contact method for follow-up
Our Commitments to You
- We will acknowledge receipt within 48 hours.
- We will provide a meaningful update within 7 days.
- We will keep you informed of our remediation progress.
- We will not take legal action against researchers who act in good faith and follow this policy.
- We will credit you publicly if you wish — and only if you wish.
Scope
This policy applies to security vulnerabilities in:
- qavric.com and any QAVRIC-operated subdomains
- QAVRIC-published software tools and repositories
- Any other system explicitly operated by QAVRIC
This policy does not cover third-party services used by QAVRIC. If you discover a vulnerability in a third-party service, please report it directly to that organization.
What We Ask of You
- Act in good faith. Do not exploit the vulnerability beyond what is necessary to demonstrate it.
- Do not access, modify, or delete data that does not belong to you.
- Do not perform denial-of-service attacks.
- Do not perform social engineering against QAVRIC personnel.
- Do not disclose the vulnerability publicly before we have had a reasonable opportunity to remediate.
- Contact us before public disclosure. We will work with you on coordinated release.
QAVRIC Research Disclosures
When QAVRIC discovers vulnerabilities in third-party systems through our own research, we follow a structured responsible disclosure process:
- We notify the affected vendor privately before any public disclosure.
- We provide a clear, reproducible description of the vulnerability.
- We allow a minimum of 90 days for remediation before any public disclosure.
- We coordinate timing with the vendor where possible.
- We publish only what is necessary to communicate the risk — no gratuitous detail.
security.txt
Our security.txt is published at the standard location. We treat it as a real operational endpoint, not decoration.