Reporting a vulnerability
If you believe you have found a security vulnerability in a Q-Feeds website, service or API, please email us at security@qfeeds.com. A machine-readable version of these contact details is published at /.well-known/security.txt (also available at /security.txt; RFC 9116).
To help us triage quickly, please include:
- A clear description of the issue and its potential impact.
- The affected URL, endpoint, host or product.
- Step-by-step reproduction details, proof-of-concept code or screenshots.
- Any accounts, IP addresses or timestamps you used during testing.
Scope
The following Q-Feeds properties are in scope:
qfeeds.comand its subdomains, including the corporate website and commerce endpoints.- The Q-Feeds Threat Intelligence Portal and public APIs operated by Q-Feeds.
The following are out of scope, and reports about them will usually not be actioned:
- Findings that require physical access, social engineering, phishing or access to a victim's device or email.
- Denial-of-service (DoS/DDoS), volumetric or brute-force attacks, and load testing.
- Reports produced solely by automated scanners without a demonstrated, exploitable impact.
- Missing best-practice headers, TLS configuration nuances, SPF/DKIM/DMARC and similar issues with no direct security impact.
- Third-party services and platforms that Q-Feeds does not operate.
Guidelines for researchers
When investigating an issue, we ask that you:
- Act in good faith and avoid privacy violations, data destruction, service degradation and disruption to other users.
- Only interact with accounts you own or have explicit permission to test.
- Access the minimum amount of data necessary to demonstrate the vulnerability, and never store, share or exfiltrate personal data.
- Give us a reasonable opportunity to resolve the issue before disclosing it publicly.
Safe harbor
We consider security research and vulnerability disclosure conducted in accordance with this policy to be authorised, and we will not pursue or support legal action against you for such research carried out in good faith. If legal action is initiated by a third party against you for activities that complied with this policy, we will make it known that your actions were authorised. If you are unsure whether a specific action is permitted, contact security@qfeeds.com before proceeding.
What to expect from us
- We aim to acknowledge your report within five business days.
- We will keep you informed as we investigate and work toward a resolution.
- We will handle your report confidentially and will not share your details with third parties without your consent, except where required by law.
Recognition
Q-Feeds does not currently operate a paid bug bounty programme. With your permission, we are happy to publicly credit researchers who responsibly report valid vulnerabilities that we resolve.
Contact
Security reports: security@qfeeds.com. For all other enquiries, please use our contact page.