Security approach
We seek to apply risk-appropriate safeguards across development, hosting, access, updates, and incident handling. Controls may change with the architecture and sensitivity of information. No system is perfectly secure, and publication of this page is not a representation of SOC 2, ISO 27001, HIPAA, or other certification.
Report a vulnerability
Email contact@qretix.ai with “Security report” in the subject. Include the affected URL or component, reproduction steps, impact, relevant screenshots or logs with secrets removed, and a safe way to contact you. Do not send live credentials, patient information, or unnecessary personal data.
Good-faith research guidelines
- Avoid privacy violations, persistence, data destruction, service degradation, and access to data beyond what is needed to demonstrate the issue.
- Do not use denial of service, social engineering, phishing, credential stuffing, physical attacks, or third-party account compromise.
- Stop testing and report promptly if you encounter sensitive data or gain unintended access.
- Allow reasonable time to investigate and remediate before public disclosure.
What to expect
We will aim to acknowledge actionable reports and communicate when practical, but do not promise a particular response or remediation time. This policy does not create a bug bounty, employment, or payment obligation. Good-faith activity that follows this policy will not be intentionally pursued by Q-RETIX AI as malicious access, subject to applicable law and third-party rights.
Security incidents
If a confirmed incident triggers legal notification duties, Q-RETIX AI will make notifications in the manner and timeframe required for the affected processing. Do not use general website content as a substitute for a product-specific security addendum or incident plan.