01Scope
This policy covers qualflare.com and its subdomains, our web application, and our API. If you've found a security issue in any of these, we want to hear about it before anyone else does.
Last updated July 4, 2026
This policy covers qualflare.com and its subdomains, our web application, and our API. If you've found a security issue in any of these, we want to hear about it before anyone else does.
Email [email protected] with a description of the issue, the steps to reproduce it, and its potential impact. Proof-of-concept code or a screen recording helps us triage faster.
Please don't open a public GitHub issue, post about the issue publicly, or test against accounts other than your own. Give us a reasonable window to investigate and address a report before disclosing it publicly.
We read every report that comes in to this address and will acknowledge it. Confirmed issues are prioritized by severity and impact; we'll let you know once a fix is out, or if we've assessed the report as out of scope or not a vulnerability.
We won't pursue legal action against anyone who makes a good-faith effort to find and report a vulnerability in accordance with this policy, including:
Report a vulnerability, or ask a question about this policy, at [email protected]. This is also the contact address published in our security.txt file.