Security Disclosure Policy
This policy explains how security researchers may report suspected vulnerabilities affecting digital services operated by Quantum Intelligence Hub LTD (“QIH”, “we”, “us” or “our”). It covers QIH websites, QIH HUB AI and AI Digital Reception services only to the extent expressly stated below.
Version 4.0Updated: 23 August 2026England and WalesCompany No. 17246860
Important: this policy is not blanket permission to test any QIH, customer or third-party system. Authorisation applies only to expressly in-scope QIH assets, within the limits below. Customer environments and third-party services are excluded unless QIH gives specific written authorisation.
1. Purpose and Good-Faith Research
We welcome clear, responsible reports that help us identify and remedy genuine security weaknesses. Researchers must act in good faith, minimise risk and interference, respect privacy, and stop testing as soon as their limited proof of concept establishes the issue.
2. In-Scope and Out-of-Scope Systems
Unless a written scope statement says otherwise, testing is limited to QIH-owned public websites and services for which QIH has authority to grant permission.
Out of scope:
- customer websites, accounts, tenants, data, dashboards and communications;
- live telephone, SIP, messaging, WhatsApp, Meta, email or social-channel accounts;
- payment processors, banks, cloud, hosting, domain, analytics and other third-party services;
- employee or contractor devices and personal accounts;
- any asset not clearly owned and controlled by QIH.
If ownership or scope is unclear, contact security@qihhub.com before testing.
3. Limited Safe Harbour
Where research is conducted in good faith, remains within this policy and applicable law, and is reported promptly, QIH will not initiate legal action solely because of that compliant research. This commitment does not authorise unlawful conduct, does not waive QIH’s rights regarding harm or policy violations, and cannot bind law-enforcement authorities, customers or third parties.
4. Permitted Testing
- low-volume, non-destructive testing of expressly in-scope assets;
- testing through accounts and data you own or are authorised to use;
- the minimum access and proof necessary to demonstrate a vulnerability;
- security misconfiguration, authentication and access-control observations that do not affect other users;
- prompt reporting followed by reasonable cooperation with validation.
5. Prohibited Activities
- denial-of-service, distributed denial-of-service, load or stress testing;
- social engineering, phishing, impersonation or physical intrusion;
- malware, ransomware, persistence, destructive payloads or backdoors;
- password spraying, credential stuffing or acquisition of third-party credentials;
- mass scanning, automated activity that creates instability, or bypassing rate limits;
- privilege escalation beyond the minimum required proof;
- altering, deleting, encrypting, extracting or retaining data;
- accessing customer communications, calls, recordings, tokens or payment information;
- extortion, threats, sale of vulnerability information or demands for payment.
6. Personal and Confidential Data
If you encounter personal, confidential, authentication or customer data, stop immediately. Do not view more than necessary, copy, download, retain, transmit or disclose it. Report the exposure securely, identify what was inadvertently observed, and delete any local material when QIH instructs you to do so. Legal data-protection duties continue to apply.
7. AI Digital Reception and Communication Systems
AI Digital Reception systems can process live business communications. Researchers must not access or test real customer conversations, call recordings, transcripts, contact lists, knowledge bases, SIP credentials, messaging tokens or payment data. Testing may occur only in a QIH-designated demo or test tenant and only with written authority.
8. How to Report
Email security@qihhub.com with the subject “Security Vulnerability Report”. Include:
- the affected URL, asset and environment;
- a concise technical description and potential impact;
- safe reproduction steps and the time of testing;
- minimal screenshots, logs or proof of concept;
- your contact details and preferred disclosure name, if any.
Do not email secrets, credentials, full datasets or unnecessary personal data. Ask us for a secure transfer method if sensitive evidence is essential.
9. What Researchers May Expect
We aim to acknowledge a valid report within three business days and provide an initial triage response within ten business days. These are operational targets, not guarantees. Complexity, third-party dependencies and urgent incident response may affect timing. Where practical, we will provide periodic status updates and notify the reporter when remediation is complete.
10. Coordinated Disclosure
Do not publicly disclose a vulnerability, exploit details or affected data before QIH has remediated the issue or agreed a disclosure date in writing. A 90-day coordination period may be used as a general reference, but critical risks or third-party dependencies may require a different agreed timetable. QIH will not unreasonably delay coordination.
11. Rewards and Recognition
QIH does not currently operate a standing bug-bounty programme. No payment, reward, employment, partnership or public recognition is guaranteed. Any reward must be expressly approved by QIH in writing before it becomes binding.
12. Third-Party Vulnerabilities
QIH cannot authorise testing of systems owned or operated by third parties. Where a suspected issue belongs to a third-party provider, follow that provider’s disclosure policy. You may also notify QIH if the issue materially affects a QIH service, but this does not expand your testing authority.
13. Responsibility and Applicable Law
Each party remains responsible for its own conduct, negligence and breach of applicable duties. Nothing in this policy excludes or limits liability where the law does not permit exclusion. Research must comply with applicable law, including the Computer Misuse Act 1990 and applicable data-protection law. This policy is governed by the laws of England and Wales, subject to mandatory rights and jurisdictional rules.
14. Guidance, Related Policies and Contact
This process is informed by the UK National Cyber Security Centre’s Vulnerability Disclosure Toolkit, including its guidance on clear reporting routes, scope and security.txt.
QUANTUM INTELLIGENCE HUB LTD
71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Security: security@qihhub.com
Legal: legal@qihhub.com
Company No. 17246860