Security & vulnerability disclosure

Quotr does not currently operate a structured bug bounty program. We cannot guarantee monetary rewards, compensation, swag, public acknowledgement, or a formal response timeline for submitted reports.

However, if you still want to disclose a potential security issue affecting quotr.ai or related Quotr services, we appreciate responsible reports and will review valid submissions in good faith.

Reporting a vulnerability

Security reports should be sent to info@quotr.ai.

Please include:

Responsible testing guidelines

Researchers should:

Out of scope

The following are generally out of scope:

Disclosure expectations

If you plan to publish information about an issue, contact us privately first and give us reasonable time to review and fix it before sharing details more widely. Those reports are usually easiest for us to prioritize and follow up on.

We appreciate responsible reports that help protect our services and customers.