runQC
Home Features Pricing Docs About Contact Request access

Security Vulnerability Disclosure Policy

Effective Date: June 4, 2026 · Last Updated: September 9, 2026 · Syntaxa LLC

Syntaxa LLC ("Company") is committed to the security of the runQC platform. We encourage responsible disclosure of security vulnerabilities and appreciate the efforts of security researchers and users who help us maintain a secure platform.


1. Scope

This policy covers security vulnerabilities in:

  • The runQC web application (app.runqc.ai)
  • The runQC API (api.runqc.ai)
  • Company-controlled infrastructure supporting the Service

This policy does not cover:

  • Third-party services (AWS, MongoDB Atlas, Stripe, OpenAI, Anthropic, Cloudflare)
  • Customer Target Agents or endpoints
  • Social engineering attacks against Company personnel

2. Reporting a Vulnerability

2.1 Contact

Report security vulnerabilities to: [email protected]

2.2 Information to Include

Please include the following in your report:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact assessment
  • Any proof-of-concept code (non-destructive)
  • Your suggested remediation (optional)

3. Our Commitments

When you report a vulnerability in good faith, Company commits to:

(a) Acknowledgment: Acknowledging receipt of your report, with a target of seventy-two (72) hours.

(b) Communication: Keeping you informed of the status of your report and the remediation timeline.

(c) Remediation: Addressing confirmed vulnerabilities according to severity:

  • Critical: Target fix within 24-72 hours
  • High: Target fix within 7 days
  • Medium: Target fix within 30 days
  • Low: Addressed in the next scheduled release

(d) No Legal Action: Not pursuing legal action against you for your research, provided you comply with this policy.

(e) Recognition: With your permission, acknowledging your contribution (name or alias) in a security acknowledgments page.


4. Your Responsibilities

When conducting security research, you must:

(a) Avoid accessing, modifying, or deleting data belonging to other users;

(b) Not exploit vulnerabilities beyond what is necessary to demonstrate the issue;

(c) Not perform denial-of-service attacks, social engineering, or physical security testing;

(d) Not publicly disclose the vulnerability until Company has had a reasonable opportunity to address it (minimum 90 days from the date of report, or until a fix is deployed, whichever comes first);

(e) Act in good faith and comply with all applicable laws.


5. Safe Harbor

Company considers security research conducted in accordance with this policy to be authorized and will not initiate legal action against you for such research. If legal action is initiated by a third party against you for activities conducted in compliance with this policy, Company will take steps to make known that your actions were authorized.


6. Out of Scope

The following are generally not considered qualifying vulnerabilities:

  • Clickjacking on pages with no sensitive actions
  • Missing security headers that do not lead to a demonstrated vulnerability
  • Missing rate limiting on non-sensitive endpoints
  • Software version disclosure
  • Vulnerabilities requiring physical access
  • Vulnerabilities in third-party dependencies without a demonstrated exploit

7. Contact

Syntaxa LLC
Security Team: [email protected]


This Security Vulnerability Disclosure Policy was last updated on September 9, 2026.

Other Legal Documents

  • Terms of Service
  • Privacy Policy
  • Acceptable Use Policy
  • Cookie Policy
  • DMCA Policy
  • Service Level Agreement
  • Data Processing Agreement
  • Beta Agreement
runQC

Comprehensive AI agent testing and verification platform for reliable deployments.

Product

  • Features
  • Pricing
  • Documentation
  • API Reference

Company

  • About
  • Contact
  • Blog
  • Careers

Legal

  • Privacy Policy
  • Terms of Service
  • Security
  • Status

© 2026 Syntaxa LLC. All rights reserved.

runQC - AI Agent Quality Control