Vulnerability Disclosure
Last updated: June 2026
We welcome responsible reports of potential security vulnerabilities affecting Quant-Kongz.
Authorization and Scope
Quant-Kongz operates a vulnerability disclosure channel, not a public bug bounty program and not an open authorization to perform penetration testing.
We welcome good-faith reports of potential security vulnerabilities. Any research must be lawful, non-destructive, non-disruptive, and limited to systems, accounts, installations, and data that you own or are expressly authorized to use.
Report a vulnerability
To report a suspected vulnerability, please email:
security@quantkongz.com
Please include
- •Affected product or component.
- •Product version, if known.
- •Operating system and environment.
- •A clear description of the issue.
- •Reasonable steps to reproduce the issue.
- •Potential security impact.
- •Your contact information, if you want us to follow up.
You must not
- •Access, modify, delete, or disclose data that does not belong to you.
- •Disrupt or degrade the availability of Quant-Kongz services.
- •Perform denial-of-service testing.
- •Perform automated scanning that may affect service availability.
- •Attempt credential attacks, brute-force attacks, phishing, spam, malware, or social engineering.
- •Test third-party services, infrastructure, brokers, trading platforms, cloud providers, or payment processors connected to Quant-Kongz.
- •Publicly disclose the vulnerability before we have had a reasonable opportunity to investigate and remediate it.
Any activity outside this scope requires prior written authorization from Quant-Kongz.
Response
We aim to acknowledge valid vulnerability reports within a reasonable timeframe and will prioritize remediation based on severity, exploitability, and potential user impact.