Responsible Disclosure

CyberAIQuantum welcomes responsible, good-faith reports of potential security vulnerabilities affecting its publicly accessible website assets. This policy explains how to report security concerns safely and confirms that intrusive testing or security assessments must not be performed without prior written authorisation.

What may be reported

  • Potential security vulnerabilities affecting publicly accessible CyberAIQuantum web assets.
  • Misconfigurations that could unintentionally expose non-public information.
  • Security issues affecting published contact or trust channels.

Do not perform

  • Denial-of-service testing.
  • Social engineering.
  • Physical attacks.
  • Accessing, modifying or deleting data that is not yours.
  • Scanning beyond public CyberAIQuantum assets without written authorisation.
  • Automated vulnerability scanning or penetration testing without prior written authorisation.

How to report

Send a clear description, affected URL, steps to reproduce and your contact details to info@cyberaiquantum.com. Do not include sensitive personal data or client information. Where possible, include screenshots or supporting evidence to help us reproduce and investigate the issue.

Response approach

CyberAIQuantum will assess all good-faith reports and prioritise investigation and remediation based on severity, exploitability and potential business impact. While every report will be reviewed, acknowledgement or remediation timescales cannot be guaranteed under this public policy.

Scope

The public disclosure route is limited to CyberAIQuantum public website assets and published contact channels. Client systems, partner systems and third-party platforms are outside scope unless expressly agreed in writing.

What we ask of researchers

  • Act in good faith.
  • Avoid disrupting services or affecting other users.
  • Do not access, modify or retain data that does not belong to you.
  • Keep findings confidential until CyberAIQuantum has had a reasonable opportunity to investigate and respond.
  • Comply with all applicable laws and regulations.


Confidentiality

We ask that security researchers do not publicly disclose potential vulnerabilities until CyberAIQuantum has had a reasonable opportunity to investigate and, where appropriate, remediate the issue.

Emergency matters

This route is not a 24/7 emergency incident response channel. Existing clients should use the escalation route stated in their engagement documentation.

Legal notice

Nothing in this policy authorises activities that would breach applicable laws or regulations. CyberAIQuantum reserves the right to investigate and respond appropriately to any activity that falls outside the scope of this policy.

Responsible disclosure reports can be submitted to:

Email: info@cyberaiquantum.com