Evidence signature
Public signals bind to governed proof.
No customer data.
QScout proof sequence. Evidence Handshake. public-to-private proof path. No customer data.
Trust & security
Qtonic Quantum welcomes coordinated reports from the security research community. This policy explains how to report a vulnerability, what is in scope, and the protections we extend to good-faith researchers.
Send your report directly to the dedicated security inbox below. It is the canonical reporting route published in our security.txt policy and is monitored for coordinated vulnerability disclosure.
A useful report typically includes:
The current PGP public key for encrypted reports is published at /pgp-key.txt. Verify the fingerprint out-of-band before sending sensitive material; we are happy to confirm it by email on request.
We will not pursue or support legal action against researchers who act in good faith and follow this policy. Specifically, we ask that you:
Activity that violates this policy or applicable law is not covered. When in doubt, ask first.
We aim to acknowledge a valid report within five business days, confirm triage status within ten business days, and provide a remediation timeline once impact is reproduced. These are aspirational targets, not contractual commitments.
We coordinate disclosure on a 90-day timeline by default. Where ecosystem dependencies require it, we will agree on a longer or shorter window with the reporter before publication.
Researchers who help us improve will be acknowledged here with their permission. This list is currently empty.
A formal bug-bounty program is in design. Leave your address and we will notify you when it opens. No spam — operational updates only.
Machine-readable contact information is published at /.well-known/security.txt per RFC 9116.