How to report a suspected vulnerability in Quantum Connect AI, what is in scope, and how we respond.
In scope: the Quantum Connect AI web application, the marketing site at quantumconnectai.com, and the APIs that serve them. Out of scope: third-party services we do not operate, social engineering of our staff or customers, physical attacks, and volumetric denial-of-service testing.
Email security@quantumconnectai.com. Include:
We acknowledge reports within one business day. We triage the report, confirm impact, and keep you updated while we remediate. Please give us a reasonable window to fix an issue before any public disclosure.
Our security posture and governance controls are documented in the Trust Center.
We will not pursue legal action against researchers who follow this policy, act in good faith, and avoid privacy violations, data destruction, and service disruption. We do not currently operate a paid bounty program.