Vulnerability reporting policy

How to report security vulnerabilities to Qminder in a responsible disclosure manner.

Qminder believes in a program that fosters collaboration amongst security professionals to help protect our systems and customers’ personal information from malicious activity due to vulnerabilities against our networks, web and mobile applications and set security policies across our organization. We treat the security and safety of our customers’ personal information with utmost importance.For the protection of our customers, Qminder does not disclose, discuss or confirm security matters until comprehensively investigating, diagnosing and fixing any known issues.

The primary contact for security vulnerabilities is security@qminder.com.

Please do not contact our Support (live chat) or support@qminder.com with security vulnerability reports.

Program rules

Program eligibility

Safe Harbor

Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

Priority system & reward tiers

Qminder uses Bugcrowd's Vulnerability Rating Taxonomy to prioritize security issues. Any security issues with P3, P4 or P5 priority will usually be scheduled for improvement later down the road - and are not eligible for a reward.

Program scope

Any third-party products that are utilized by Qminder (such as Google Analytics, TrackJS, Intercom, et al) are out of scope!

Included:

Excluded:

Excluded vulnerabilities

The following categories of reports are considered out of scope for our program and will not be rewarded:

Qminder reserves the right to add to and subtract from the Exclusions list depending on the evaluated severity of reported vulnerabilities and risk acceptance.

Rewards

As a general guideline, Qminder does not reward security issues with a Bugcrowd VRT priority level less than P3.

All bounty amounts will be at the discretion of the Qminder Bug Bounty team and will be evaluated for severity, impact, and quality of the report. There could be submissions for which we accept the risk and will not fix.

Qminder uses the Bugcrowd VRT priority level as a helping tool to help decide on if to reward a bug submission. Our reward panel will review each vulnerability submission for eligibility and final reward consideration. Final reward amounts are at the sole and final discretion of Qminder's reward panel. In some instances, our reward panel may choose higher rewards for unusually major, clever or complex vulnerability submissions.

If we receive several reports for the same issue, we offer the reward to the earliest report for which we have enough actionable information to identify the issue. If a single fix resolves multiple vulnerabilities, we treat this as a single vulnerability, which will receive a single bounty.

Rewards may be reduced or declined if there is evidence of abuse, such as data exfiltration or withholding reports in order to chain multiple issues together.

What to include in your report

A well-written report will allow us to more quickly and accurately triage your submission.

Please be aware that the quality of your report is critical to our evaluation of your submission. We encourage you to use the list below as a template for your report. This does NOT mean you need to fully exploit the issue, just provide the information with as much detail as possible.

Legal

Qminder reserves the right to modify terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this site regularly as we routinely update our program terms and eligibility, which are effective upon posting. We reserve the right to cancel this program at any time. Must be 18 or older to be eligible for an award.