QReportly

QReportly

Sign in

Security contact

Responsible Disclosure Policy

We welcome good-faith reports of security issues in the QReportly platform. This page tells researchers what is in scope, how to contact us, and what we will not treat as authorised testing.

Last updated: 31 August 2026

01

Purpose

Qreportly LLC ("QReportly") operates a confidential whistleblowing SaaS. We want researchers to tell us about vulnerabilities so we can fix them before they harm customers or reporters.

This policy is not a paid bug-bounty programme and does not authorise activity that would be unlawful if this page did not exist.

02

Scope

In scope: the production QReportly web application, the public reporting channel, the company dashboard, partner and designated-officer surfaces operated by QReportly, and related APIs on qreportly.com.

Out of scope: third-party systems we do not operate (for example Stripe, Google, Vercel, Supabase infrastructure outside our application), physical security, social engineering of staff or customers, denial-of-service, spam, and testing against another customer's workspace.

03

How to report

Send reports to contact@qreportly.com.

Use a clear subject line such as "Security report — [short description]". Do not attach live credentials, customer data, or exploit payloads.

04

What to include

A useful report describes the affected URL or feature, the impact on confidentiality, integrity or availability, and the steps needed to reproduce the issue at a high level — without a weaponised proof of concept.

  • Affected product surface (public channel, dashboard, partner, officer, API).
  • Your observation of impact (for example: unauthorised access to another organisation's case).
  • Approximate time of the observation and your contact details.
  • Do not include passwords, session tokens, other customers' data, or attack scripts.

05

Good-faith research

If you follow this policy, stay within scope, do not access or retain other customers' data beyond the minimum needed to demonstrate the issue, and do not disrupt the service, Qreportly LLC will not initiate legal action against you for that research.

This statement does not waive rights against anyone who ignores this policy, accesses data they do not own, or causes harm. It is not permission to break the law.

06

Our response

We aim to acknowledge reports within five business days. We may ask clarifying questions. We will not publish a researcher-by-researcher SLA, and we do not currently run a paid bounty.

Please give us a reasonable time to investigate before any public discussion. We will credit researchers who request it only with their consent and without disclosing sensitive details.

07

What not to do

Do not attempt to access another organisation's reports, members, or files. Do not degrade availability. Do not phish our staff or customers. Do not scan in a way that generates abusive traffic.

08

Contact

Security: contact@qreportly.com. Provider: Qreportly LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA.

Security: contact@qreportly.com. Provider: Qreportly LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA.