Skip to main content

Responsible disclosure

Report security concerns privately and safely.

Good-faith security reports help protect Qedix users. This policy explains the authorized channel, expected report content, research boundaries, and coordination process.

Policy scope

What this reporting process is intended to cover.

In scope

  • Qedix public web pages and authenticated web application.
  • Qedix-owned API behavior exposed to authorized users.
  • The Qedix GitHub App and its customer-visible integration.
  • Authentication, authorization, data exposure, or security control issues directly involving Qedix.

Outside this authorization

  • Third-party products or infrastructure not controlled by Qohere.
  • Testing another customer’s account, organization, or repository.
  • Denial-of-service, destructive, disruptive, or high-volume testing.
  • Social engineering, phishing, physical attacks, spam, or credential theft.

This policy does not grant access to private systems, customer repositories, internal environments, employee accounts, or third-party services.

What to include

A focused report helps Qohere evaluate the concern without unnecessary sensitive data.

  1. 01

    A concise description of the suspected vulnerability and its potential impact.

  2. 02

    The affected Qedix URL, workflow, or customer-visible component.

  3. 03

    Clear reproduction steps using the minimum access and data necessary.

  4. 04

    The date and approximate time of testing, including the relevant time zone.

  5. 05

    Safe evidence such as sanitized screenshots, request details, or logs with credentials removed.

  6. 06

    Your preferred contact information for coordinated follow-up.

Good-faith research rules

Research must remain authorized, proportionate, and non-destructive.

  • Rule 01

    Test only accounts, repositories, and information you own or are explicitly authorized to access.

  • Rule 02

    Use the minimum number of requests and the least-invasive method needed to demonstrate the issue.

  • Rule 03

    Do not access, retain, alter, destroy, or disclose another customer’s data.

  • Rule 04

    Do not use social engineering, phishing, credential theft, physical intrusion, denial of service, or high-volume automated scanning.

  • Rule 05

    Do not establish persistence, deploy malware, exfiltrate source code, or move beyond the minimum proof required.

  • Rule 06

    Stop testing immediately if you encounter credentials, secrets, personal data, or customer repository content that you are not authorized to access.

  • Rule 07

    Give Qohere a reasonable opportunity to investigate and address the issue before public disclosure.

If customer data appears

Protecting customer information takes priority over continued testing.

If a credential belonging to you is exposed, revoke or rotate it promptly. Do not send the credential itself to Qohere.

What happens after a report

The process may vary with severity, complexity, and affected parties.

01

Receive

Qohere reviews the report for sufficient information and confirms an appropriate contact channel.

02

Assess

The report is evaluated for reproducibility, affected scope, severity, and potential customer impact.

03

Coordinate

Qohere may request clarification, provide progress updates, and discuss a responsible disclosure timeline.

04

Resolve

Where a valid issue is confirmed, Qohere works toward remediation and appropriate customer communication.

Response and remediation time depends on reproducibility, severity, technical complexity, customer impact, and required coordination. Qohere does not promise a fixed remediation deadline.

Good-faith safe harbor

How Qohere intends to treat research that follows this policy.

This statement does not authorize unlawful activity, does not waive the rights of third parties, and cannot bind law-enforcement agencies or third-party service providers. If you are uncertain whether a test is permitted, contact Qohere before testing.

Recognition and rewards

What reporters should expect from the current public beta.

No bug-bounty program

Qohere does not currently operate a paid bug-bounty program and does not promise payment, public recognition, or other rewards. Any recognition is voluntary and requires the reporter’s consent.

Private reporting channel

Use a clear subject line so the report can be identified quickly.

Email

info@qohere.in

Suggested subject: Private Qedix security report

Effective date: July 14, 2026. This policy may be updated as the Qedix security-reporting process evolves.