← Back to home Security

Report a vulnerability

Qwing ships hybrid post-quantum end-to-end encryption, and its own protocol. If you find a flaw in it — in the cryptography, in the apps, in the server, or in anything that ships — we want to hear about it, and we will tell you what we are doing about it. This page is the public vulnerability-disclosure policy for Qwing (CODEARMORY). It is published at a stable URL (qwing.app/security.html) and is the policy referenced by qwing.app/.well-known/security.txt.

1. How to report

2. What we do, and when

These are commitments, not aspirations. Every report gets a human answer inside these windows.

WithinWhat happens
24 hoursWe acknowledge your report. If it describes something exploitable, we start triage immediately and tell you what we have understood so far.
72 hoursWe send an assessment: whether it reproduces, our severity view, the affected releases, and the action plan with the dates we are working to. If we cannot reproduce it, we say so and ask for what we need.
ThenWe keep you updated at every meaningful step — when a fix is written, when it ships, and when it is available to users. Critical and high-severity issues are fixed and released before we publish anything about them.
PublicationWe publish an advisory once a fix is available, with your report credited under the name you choose (or anonymously). We ask you to hold publication until then, and we will not hold it longer than the fix takes.

3. Cyber Resilience Act

Qwing is a product with digital elements placed on the EU market, so the manufacturer's obligations of Regulation (EU) 2024/2847 (the Cyber Resilience Act) apply to it, including coordinated vulnerability disclosure and reporting. In practice that means:

4. Safe harbour

If you report in good faith and follow this policy, we will not pursue legal action against you or ask anyone else to, and we will say publicly that your research was authorised. In return, we ask you to:

5. What is in scope

Out of scope: findings that need a rooted or jailbroken device or physical access to an unlocked phone (we describe those threats in the threat model instead); missing hardening headers on static pages with no user data; reports produced only by an automated scanner with no demonstrated impact; and third-party services we do not control (the app stores, APNs/FCM, coturn's upstream code).

6. Payment

There is no bug bounty. We are a small project and we would rather tell you that plainly than imply a reward we cannot pay. What we do give is the timeline above, a fix, credit if you want it, and an answer to every question you ask about what we did.

7. Advisories

Advisories and the status of every internal review are recorded in the repository's audit directory (this document set becomes public with the source). No independent third-party audit has been completed yet, and we say so wherever we describe the security of the product.