Vulnerability Disclosure Policy
In one line
How to report a security problem to us, what we promise in return, and the rules that keep your research safe and legal.
The short version
This short version helps you understand the full text. Read the full text for the complete terms.
- Email security@qypu.ai with what you found and how to reproduce it. (Full text, section 2)
- We reply within 2 working days and keep you updated. (Section 3)
- If you follow these rules in good faith, we will not take legal action against you. (Section 4)
- Do not access other people's data, disrupt the service, or publish before we fix it. (Section 5)
- We have no paid bug bounty yet. We are happy to credit you. (Section 6)
Full text
Read the full text (about 1 minute)
1. Scope
In scope: qypu.ai, app.qypu.ai, and our public API endpoints. Out of scope: admin.qypu.ai brute-force attempts, third-party platforms (report to them), denial-of-service tests, social engineering, and physical attacks.
2. How to report
Send a report to security@qypu.ai. Include the affected URL or component, steps to reproduce, impact, and your contact details. Please encrypt sensitive details if you can; [PGP KEY — planned].
3. Our commitments
- Acknowledge your report within 2 working days.
- Give an initial assessment within 7 days.
- Aim to fix critical issues within 7 days and high-severity issues within 30 days of confirmation.
- Tell you when the issue is fixed, and agree a disclosure date with you (normally within 90 days).
4. Safe harbour
If you make a good-faith effort to follow this policy, we will consider your research authorised, we will not pursue legal action against you, and we will not report you to authorities for it. If a third party takes action, we will make it known that your research was authorised. This does not bind other parties, such as platforms.
5. Rules
- Use only your own test accounts and test workspaces.
- Stop and tell us as soon as you reach personal data, tokens, or another customer's information. Do not keep, share, or use it.
- Do not degrade the service, send spam, or publish to real social channels.
- Do not publish details before the agreed date.
6. Recognition
We do not run a paid bug bounty yet. With your permission, we will credit you on our change log.
7. Machine-readable contact
/.well-known/security.txt (RFC 9116).
Change log
- 2026-10-10 · 0.1.0 · First draft.
Open questions for counsel
We publish these while the page is a draft, so you can see what is not settled yet.
- Safe harbour wording: confirm effect under the US CFAA and DMCA, the UK Computer Misuse Act 1990, and equivalents; it cannot authorise testing of third-party platforms.
- Confirm the security mailbox exists and is monitored before publishing security.txt.
Useful for: IT and security reviewers, Platform reviewers. To save this page as a PDF, use your browser's Print command. Back to the trust centre.