Skip to content
qaso.
ProductsArchitectureDocsConsoles
Home

Security and vulnerability disclosure

Last updated 26 September 2026

If you believe you have found a security vulnerability in QASO software or in our websites, please tell us. We would rather hear it from you first.

How to report

Email security@qaso.ai. Please include what you found, where (the URL, product and version), how to reproduce it, and the impact you expect. Please do not include real customer data. If you need an encrypted channel, say so in your first message and we will arrange one.

A machine-readable version of this contact is at /.well-known/security.txt.

What to expect

  • We aim to acknowledge your report within 3 business days.
  • We will keep you informed as we investigate and fix, and tell you when it is resolved.
  • We do not currently run a paid bounty programme.

Scope

In scope: qaso.ai and the secure.qaso.ai, assure.qaso.ai and soar.qaso.ai sites and consoles, and the QASO appliance and server software we distribute (Secure, Assure and SOAR).

Out of scope: third-party services we rely on (for example Google sign-in, cloud providers, GitHub); social engineering or physical attacks; denial-of-service or high-volume automated scanning (our sites rate-limit, so please keep request rates low); and testing against accounts or data that are not yours.

Good-faith research

If you act in good faith and follow this policy, we will treat your research as authorised. Please avoid accessing, changing or destroying data that is not yours, do not degrade the service for others, and stop and tell us if you reach data that is not yours. Please give us a reasonable time to fix a problem before you disclose it publicly.

Assurance status

QASO does not currently hold a SOC 2 report or an ISO/IEC 27001 certificate. If you are evaluating QASO and need to understand our current security practices, email support@qaso.ai.

QASOPrivacy · Security