QNSI

Vulnerability Disclosure Policy

How to report a security vulnerability in QNSI, what we commit to in return, and the safe harbour that protects good-faith research.

Last updated: 2026-07-13 · Effective: 2026-07-13

How to report

Send findings to qnsi-security@heossi.com. Our machine-readable contact is published at https://qnsi.heossi.com/.well-known/security.txt (RFC 9116).

Please include: what you found, where, the impact, and the minimum steps to reproduce. If you have a proof of concept, include it. Do not include third-party data.

What we commit to

  • We acknowledge reports within 3 business days.
  • We give you an initial assessment (accepted / duplicate / not-a-vulnerability, and a severity) within 10 business days.
  • We keep you updated on remediation progress, and we tell you when it ships.
  • We will credit you publicly if you want credit, and stay quiet if you do not.

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will not pursue or support legal action against you, and we will treat your activity as an authorised engagement for the purposes of the Acceptable Use Policy.

Good faith means: you did not access, modify, or exfiltrate data belonging to another tenant; you did not degrade the service; you stopped as soon as you demonstrated the issue; and you gave us a reasonable opportunity to fix it before disclosing.

Out of scope

  • Denial of service, volumetric attacks, and resource-exhaustion testing against production.
  • Social engineering of HEOSSI staff, customers, or vendors; physical attacks.
  • Findings that only affect an unsupported or out-of-date client, or that require a compromised endpoint.
  • Reports generated solely by an automated scanner with no demonstrated impact.

Cryptographic findings

Cryptographic issues are our highest-severity class. If you believe you have found a flaw in a QNSI cryptographic path — key handling, envelope encryption, the audit-chain signatures, cross-verification, or a NIST-conformance claim — say so explicitly in the subject line and we will escalate immediately.