Quantum
Login Resources
Knowledge Base Blog Webinars
Contact Us
Quantum
  • Quantum Security
  • Why Quantum
    Why Quantum? How We Work
  • Capabilities
    Detection and Response Detection and Response XDR+SOC Continuously detect & respond. Vulnerability Management Vulnerability Management VA/PT Continuously scan & remediate. Data Protection Data Protection Data Protection Discover & protect sensitive data. Risk Management Risk Management GRC Manage risk with one framework.
  • Solutions

    By Industry

    Financial ServicesSolutions for FinTech & traditional
    financial services firms
    HealthcarePHI and medical research security
    & compliance solutions
    OT and IoT SystemsIndustrial and high-tech operations
    security and risk solutions.
    Software and SaaSSolutions integrated with continuous
    deployment value streams.
  • Company
    About Us Contact Us
Request Demo Solution Builder Login to Support Portal
  • Corporate Information
  • Terms of Use
  • Acceptable Use Policy (AUP)
  • Service Level Agreement (SLA)
  • General Terms & Conditions
  • Penetration Testing
  • Personal Data Protection Policy
  • Contributor License Agreement
  • Responsible Disclosure Policy
  • OSS Code of Conduct

Responsible Disclosure Policy

Last Updated: 14 July 2021

The Quantum team and community strive to provide products that are free of bugs that would impact the privacy and security of your data and resources. We are dedicated to maintain responsible disclosure and make every effort to close any gaps found within our platform or product that is within our scope to correct. We appreciate the dedication and effort to responsibly disclose security findings, and will make every effort to acknowledge contributors.

To report a security issue, email security.oss@quantum.security and include the word "SECURITY" in the subject line.

The Quantum team will respond in acknowledgement of your report. After the initial reply to your report, the security team will investigate and provide updates towards the resolution and a timeline regarding a full announcement. We may ask for additional information or guidance so please be sure to include a way to contact you.

Report security bugs in third-party modules to the person or team maintaining the module. You may also report a vulnerability through the various package registries' responsible reporting processes.

Disclosure Policy

When Quantum's security team receives a security bug report, they will assign it to a primary handler. This person will coordinate the fix and release process, involving the following steps:

  • Confirm the problem and determine the affected versions.
  • Audit code to find any potential similar problems.
  • Prepare fixes for all releases still under maintenance. These fixes will be released as fast as possible to the project(s) respective package registries.

Comments on this Policy

If you have suggestions on how this process could be improved please submit a pull request.

Quantum Logo

Telephone Icon +65 6681 6609 E-Mail Icon [email protected] Location Pin Icon view all locations
  • Why Quantum
    • Why Quantum?
    • How We Work
  • Capabilities
    • XDR+SOC
    • VA/PT
    • Data Protection
    • GRC
  • Solutions
    • Financial Services
    • Healthcare
    • Operational Technology
    • Software
  • Company
    • About Us
    • Contact Us
  • Resources
    • Knowledge Base
    • Blog
    • Webinars
    • Portal
Request a Demo Build Your Solution Request a Free Cyber Health Check
LinkedIn – Quantum Security Twitter - @quantum_secops YouTube GitHub - quantum-sec

© 2021 ST Telemedia Cloud Pte. Ltd. Quantum Security is part of the ST Telemedia Cloud group.

Legal Information Terms of Use Personal Data Protection Policy

This Site Uses Cookies

We use cookies to enhance browsing and personalise your experience. By continuing you are consenting to the use of cookies. You may opt out of cookie usage but certain site features may be unavailable.

Accept Opt-Out