How we handle your systems, your data, and our own product.
The short version, for anyone deciding whether to talk to us. Component-level architecture, control scope, assessment evidence, and configuration detail are shared with qualified parties during diligence, under agreement.
Authorized, minimal, recorded.
Where the boundary is, and what is not there yet.
In qore, or in this website.
Use the support route and mark the message as a security report. Describe the class of issue; do not include exploit details, secrets, or sensitive data in the first message. We acknowledge within two business days and agree a disclosure timeline with you. No advisories have been published to date.
The detail, under agreement.
Component-level architecture, security-control scope and deployment assumptions, compatibility and performance methodology with the measurements behind it, control mappings, licensing and continuity terms, and detailed direction are shared with evaluators before a decision, under an agreement that fits the conversation.