Skip to content
qikfox

Legal

Responsible Disclosure Policy

If you have found a vulnerability in a qikfox product or service, we want to hear about it, and we will not take action against you for reporting it in good faith under this policy.

Editable placeholder: Template document. Confirm the response times and safe-harbour wording with qualified counsel, and add your security contact address and PGP key before publishing.

1. How to report

Send reports through the Security Center. Add your dedicated security address and PGP key there. Please do not use general support, and please do not report vulnerabilities publicly before we have had a chance to fix them.

2. What to include

  • the affected product, platform and version;
  • a clear description of the issue and its impact;
  • reproduction steps, ideally minimal;
  • any proof-of-concept code, logs or screenshots.

3. In scope

qikfox Search, qikfox Safe Browser, qikfox Antivirus, qikfox VPN, this website and the services these products depend on.

4. Out of scope

  • reports generated by automated scanners with no demonstrated impact;
  • missing security headers or best-practice suggestions without an exploit path;
  • social engineering of our staff or users, and physical attacks;
  • denial of service through volume alone;
  • issues in third-party services we do not control;
  • a browser rendering content it was asked to render, absent a security-boundary failure.

5. Rules of engagement

  • test only against your own accounts and devices;
  • do not access, modify or exfiltrate data belonging to anyone else;
  • do not degrade the service for other users;
  • stop as soon as you have proven the issue, and tell us.

6. What to expect from us

  • acknowledgement that your report was received;
  • an assessment of severity and a decision on whether we can reproduce it;
  • updates as we work on a fix;
  • credit in the advisory if you would like it, or anonymity if you prefer.

Publish your specific target response and remediation windows in this section.

7. Safe harbour

If you make a good-faith effort to follow this policy, we will treat your research as authorised, will not pursue or support legal action against you, and will work with you if a third party does.

8. Coordinated disclosure

We aim to publish an advisory once a fix has shipped and users have had a reasonable opportunity to update. Published advisories appear in the Security Center.

Related qikfox pages

Found something?

A clear report with reproduction steps is the single most valuable thing you can send us.