Qwestly

Bug Bounty Program

Our Commitment to Security

We take the security of our users and systems seriously. Our bug bounty program encourages security researchers to responsibly disclose vulnerabilities, helping us keep our platform safe for everyone.

Scope

We welcome reports for vulnerabilities in our production systems and applications. Please focus on issues that could impact the confidentiality, integrity, or availability of our services. Out-of-scope submissions include social engineering, denial of service, and issues in third-party services.

Rewards

Rewards are determined on a case-by-case basis, depending on the severity and impact of the vulnerability. We appreciate your efforts and will recognize valuable contributions appropriately.

Rules

  • Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue.
  • Do not access, modify, or delete data that does not belong to you.
  • Respect user privacy and comply with all applicable laws.
  • Give us reasonable time to resolve the issue before public disclosure.

How to Report

Please send your findings to security@qwestly.com with detailed steps to reproduce the issue. Include any relevant screenshots or proof-of-concept code.

Response Process

We will acknowledge your report within 3 business days and keep you informed as we investigate and resolve the issue. We appreciate your patience and responsible disclosure.