Vulnerability Disclosure

Last updated: June 2026

We welcome responsible reports of potential security vulnerabilities affecting Quant-Kongz.

Authorization and Scope

Quant-Kongz operates a vulnerability disclosure channel, not a public bug bounty program and not an open authorization to perform penetration testing.

We welcome good-faith reports of potential security vulnerabilities. Any research must be lawful, non-destructive, non-disruptive, and limited to systems, accounts, installations, and data that you own or are expressly authorized to use.

Report a vulnerability

To report a suspected vulnerability, please email:

security@quantkongz.com

Please include

  • Affected product or component.
  • Product version, if known.
  • Operating system and environment.
  • A clear description of the issue.
  • Reasonable steps to reproduce the issue.
  • Potential security impact.
  • Your contact information, if you want us to follow up.

You must not

  • Access, modify, delete, or disclose data that does not belong to you.
  • Disrupt or degrade the availability of Quant-Kongz services.
  • Perform denial-of-service testing.
  • Perform automated scanning that may affect service availability.
  • Attempt credential attacks, brute-force attacks, phishing, spam, malware, or social engineering.
  • Test third-party services, infrastructure, brokers, trading platforms, cloud providers, or payment processors connected to Quant-Kongz.
  • Publicly disclose the vulnerability before we have had a reasonable opportunity to investigate and remediate it.

Any activity outside this scope requires prior written authorization from Quant-Kongz.

Response

We aim to acknowledge valid vulnerability reports within a reasonable timeframe and will prioritize remediation based on severity, exploitability, and potential user impact.