Vulnerability Disclosure

Last updated: July 26, 2026

We welcome responsible reports of potential security vulnerabilities affecting Quant-Kongz.

Authorization and Scope

Quant-Kongz operates a vulnerability disclosure channel, not a public bug bounty program and not an open authorization to perform penetration testing.

We welcome good-faith reports of potential security vulnerabilities. Any research must be lawful, non-destructive, non-disruptive, and limited to systems, accounts, installations, and data that you own or are expressly authorized to use.

Report a vulnerability

To report a suspected vulnerability, please email:

security@quantkongz.com

Please include

  • •Affected product or component.
  • •Product version, if known.
  • •Operating system and environment.
  • •A clear description of the issue.
  • •Reasonable steps to reproduce the issue.
  • •Potential security impact.
  • •Your contact information, if you want us to follow up.

You must not

  • •Access, modify, delete, or disclose data that does not belong to you.
  • •Disrupt or degrade the availability of Quant-Kongz services.
  • •Perform denial-of-service testing.
  • •Perform automated scanning that may affect service availability.
  • •Attempt credential attacks, brute-force attacks, phishing, spam, malware, or social engineering.
  • •Test third-party services, infrastructure, brokers, trading platforms, cloud providers, or payment processors connected to Quant-Kongz.
  • •Publicly disclose the vulnerability before we have had a reasonable opportunity to investigate and remediate it.

Any activity outside this scope requires prior written authorization from Quant-Kongz.

Response

We aim to acknowledge valid vulnerability reports within a reasonable timeframe and will prioritize remediation based on severity, exploitability, and potential user impact.