Legal Center
Legal

Security & Responsible Disclosure

Security is a shared responsibility. This page describes Q-RETIX AI’s public reporting channel and safe-harbor expectations without making an unsupported certification or audit claim.

Last updated September 17, 2026

01

Security approach

We seek to apply risk-appropriate safeguards across development, hosting, access, updates, and incident handling. Controls may change with the architecture and sensitivity of information. No system is perfectly secure, and publication of this page is not a representation of SOC 2, ISO 27001, HIPAA, or other certification.

02

Report a vulnerability

Email contact@qretix.ai with “Security report” in the subject. Include the affected URL or component, reproduction steps, impact, relevant screenshots or logs with secrets removed, and a safe way to contact you. Do not send live credentials, patient information, or unnecessary personal data.

03

Good-faith research guidelines

  • Avoid privacy violations, persistence, data destruction, service degradation, and access to data beyond what is needed to demonstrate the issue.
  • Do not use denial of service, social engineering, phishing, credential stuffing, physical attacks, or third-party account compromise.
  • Stop testing and report promptly if you encounter sensitive data or gain unintended access.
  • Allow reasonable time to investigate and remediate before public disclosure.
04

What to expect

We will aim to acknowledge actionable reports and communicate when practical, but do not promise a particular response or remediation time. This policy does not create a bug bounty, employment, or payment obligation. Good-faith activity that follows this policy will not be intentionally pursued by Q-RETIX AI as malicious access, subject to applicable law and third-party rights.

05

Security incidents

If a confirmed incident triggers legal notification duties, Q-RETIX AI will make notifications in the manner and timeframe required for the affected processing. Do not use general website content as a substitute for a product-specific security addendum or incident plan.