Vulnerability disclosure

Found something? Tell us. We will not come after you.

Good-faith research within this policy is authorised. We acknowledge within 2 business days and keep you updated until it is fixed.

In scope

  • alt.qa and its subdomains
  • The Scan and Hit browser extensions
  • The alt.qa API (once public)

Out of scope

  • Denial of service, spam, social engineering, physical attacks
  • Third-party services we use (report to them directly)
  • Missing best-practice headers without a demonstrated impact

Please

  • Give us reasonable time to fix before disclosure (we aim for 90 days).
  • Avoid privacy violations and data destruction; use your own test accounts.
  • Stop and report as soon as you reach customer data.

Safe harbour

If you follow this policy we consider your research authorised, will not pursue legal action, and will credit you publicly if you wish. We do not yet run a paid bounty.