Syntaxa LLC ("Company") is committed to the security of the runQC platform. We encourage responsible disclosure of security vulnerabilities and appreciate the efforts of security researchers and users who help us maintain a secure platform.
This policy covers security vulnerabilities in:
This policy does not cover:
Report security vulnerabilities to: [email protected]
Please include the following in your report:
When you report a vulnerability in good faith, Company commits to:
(a) Acknowledgment: Acknowledging receipt of your report, with a target of seventy-two (72) hours.
(b) Communication: Keeping you informed of the status of your report and the remediation timeline.
(c) Remediation: Addressing confirmed vulnerabilities according to severity:
(d) No Legal Action: Not pursuing legal action against you for your research, provided you comply with this policy.
(e) Recognition: With your permission, acknowledging your contribution (name or alias) in a security acknowledgments page.
When conducting security research, you must:
(a) Avoid accessing, modifying, or deleting data belonging to other users;
(b) Not exploit vulnerabilities beyond what is necessary to demonstrate the issue;
(c) Not perform denial-of-service attacks, social engineering, or physical security testing;
(d) Not publicly disclose the vulnerability until Company has had a reasonable opportunity to address it (minimum 90 days from the date of report, or until a fix is deployed, whichever comes first);
(e) Act in good faith and comply with all applicable laws.
Company considers security research conducted in accordance with this policy to be authorized and will not initiate legal action against you for such research. If legal action is initiated by a third party against you for activities conducted in compliance with this policy, Company will take steps to make known that your actions were authorized.
The following are generally not considered qualifying vulnerabilities:
Syntaxa LLC
Security Team: [email protected]
This Security Vulnerability Disclosure Policy was last updated on September 9, 2026.