Site icon Qrious Insight

Vulnerability Disclosure Policy

Effective: June 2026 · Last updated: June 2026

Our commitment

Qrious Insight takes the security of our systems and the protection of our customers’ data seriously. We value the work of the security research community, and we welcome reports of potential vulnerabilities in our products and services. This policy explains how to report a security issue to us, what is in scope, what you can expect from us, and the protections we extend to good-faith researchers.

How to report a vulnerability

Email security@qriousinsight.com.

To help us assess and reproduce the issue quickly, please include:

Please send one issue per report where possible, and avoid including real customer data in your submission.

Scope

In scope:

Out of scope:

If you are unsure whether something is in scope, contact us before testing and we will be happy to clarify.

Safe harbour

We consider security research and vulnerability disclosure conducted in accordance with this policy to be authorised conduct. When you make a good-faith effort to comply with this policy during your research, we will:

If legal action is initiated by a third party against you for activity that was conducted in accordance with this policy, we will take steps to make it known that your actions were authorised. This safe harbour applies only to good-faith research that respects the rules below; it does not authorise activity that is illegal in your jurisdiction or that harms our customers or systems.

Rules of engagement

To stay within this policy and the safe harbour above, we ask that you:

If you inadvertently access sensitive data (such as personal data or credentials) during your research, stop, do not retain or share it, and tell us in your report.

What you can expect from us

When you report in line with this policy, we will:

Coordinated disclosure

We are committed to coordinated disclosure. Please give us a reasonable opportunity to remediate before disclosing any vulnerability publicly, and coordinate the timing of any public disclosure with us. We are happy to discuss disclosure timelines and to acknowledge your contribution publicly once an issue is resolved, if you wish.

Rewards

This is a vulnerability disclosure programme. We do not currently offer monetary rewards, but we are grateful for your help and are happy to credit researchers who report valid issues.

Contact

Security reports: security@qriousinsight.com

Machine-readable version of this contact information: https://qriousinsight.com/.well-known/security.txt

Exit mobile version