1. Introduction
Quantumize Inc. takes the security of its systems and the privacy of the people who use them seriously. If you discover a security vulnerability in any Quantumize-operated system, we ask that you disclose it to us responsibly. This policy describes how to report vulnerabilities, what you can expect from us, and the legal protections we extend to good-faith researchers.
2. Scope
This policy applies to the following Quantumize-operated systems:
- The Quantumize website at https://quantumize.com and its subdomains
- The Quantumize web application and any customer-accessible interfaces
- APIs publicly accessible under the quantumize.com domain
Systems operated by third-party vendors or service providers are outside this scope. If you discover a vulnerability in a third-party system that affects Quantumize, please report it to the third-party vendor directly and, where appropriate, notify us at the contact address below.
3. Out-of-Scope Testing
The following activities are outside the scope of this policy and are not authorized:
- Accessing, modifying, or deleting data that does not belong to your own test account
- Executing denial-of-service, volumetric, or resource-exhaustion attacks
- Social engineering, phishing, or physical security testing directed at Quantumize personnel
- Automated scanning tools that generate excessive traffic or degrade system performance
- Testing third-party systems or services that integrate with Quantumize
- Vulnerabilities in systems or software not listed under Scope
4. How to Report a Vulnerability
To report a security vulnerability, send an email to security@quantumize.com with the subject line 'Security Vulnerability Report'. If you are unable to reach us at that address, you may contact us at info@quantumize.com.
Please include the following information in your report:
- A clear description of the vulnerability and its potential impact
- The affected URL, endpoint, or system component
- Steps to reproduce the issue, including any relevant payloads or proof-of-concept code
- The version or environment in which you observed the issue, if known
- Your contact information so we can follow up with you
You may submit your report in English. We will acknowledge receipt within five (5) business days.
5. Our Commitments to Researchers
When you report a vulnerability in good faith and in accordance with this policy, Quantumize commits to the following:
- Acknowledgment of your report within five (5) business days of receipt
- An initial assessment of the reported issue within fifteen (15) business days
- Keeping you informed of progress toward resolving a confirmed vulnerability
- Notifying you when the vulnerability is resolved, subject to any legal or operational constraints
- Not initiating or recommending legal action against you for good-faith testing and reporting that complies with this policy
We do not currently operate a paid bug bounty program. We do recognize researchers who identify and responsibly disclose significant vulnerabilities, subject to their consent.
6. Safe Harbor
Quantumize considers vulnerability research and disclosure conducted in accordance with this policy to be authorized conduct. We will not pursue civil or criminal action against researchers who:
- Comply with all requirements of this policy
- Make a good-faith effort to avoid privacy violations, disruption of service, and data destruction
- Report the vulnerability to us before disclosing it publicly
- Do not exploit the vulnerability beyond the minimum necessary to demonstrate the issue
This safe harbor does not extend to activities that violate applicable law independent of this policy, such as unauthorized computer access, data theft, extortion, or activities explicitly excluded by the Out-of-Scope section above.
7. Coordinated Disclosure
We ask that you give us a reasonable amount of time to investigate and address a reported vulnerability before any public disclosure. We aim to resolve critical vulnerabilities within ninety (90) days of confirmation. If you believe a vulnerability poses an immediate risk to users, please communicate that urgency in your report and we will prioritize accordingly.
If you plan to present your research at a conference or in a publication, please notify us in advance so we can coordinate disclosure timing.
8. Contact
Security reports: security@quantumize.com
General inquiries: info@quantumize.com
Quantumize Inc., 845 United Nations Plaza, New York, NY 10017, US.
This policy was last updated on July 10, 2026.

