In scope
- Qedix public web pages and authenticated web application.
- Qedix-owned API behavior exposed to authorized users.
- The Qedix GitHub App and its customer-visible integration.
- Authentication, authorization, data exposure, or security control issues directly involving Qedix.