COORDINATED DISCLOSURE

Vulnerability Disclosure Policy

This policy defines good-faith security research, prohibited activities, handling of sensitive evidence and coordinated disclosure.

01

In scope

  • quantumsafe.mobile-id.vn and explicitly listed demonstration endpoints.
  • Published QuantumSafe product releases and pilot packages supplied for testing.
  • API/documentation errors that create a security impact.
  • Authentication, authorization, cryptographic misuse, injection, data exposure and supply-chain issues.

02

Out of scope / prohibited

  • Denial-of-service, destructive or high-volume testing.
  • Social engineering, phishing or physical intrusion.
  • Accessing, retaining or modifying another party’s data.
  • Persistence, lateral movement or credential harvesting.
  • Testing production customers without written authorization.
  • Publishing unredacted secrets or personal information.

03

Good-faith expectations

Use the minimum access necessary, stop when sensitive data is encountered, preserve evidence securely, allow reasonable remediation time and coordinate disclosure with PSIRT. Mobile-ID will evaluate safe-harbor language with legal counsel before production publication; this draft does not create a legal waiver.

04

Disclosure process

TopicPolicy
CommunicationUse the PSIRT tracking ID and agreed secure channel
Status updatesProvided based on severity and remediation complexity
CVERequested/assigned where applicable and approved
Public disclosureCoordinated after mitigation or agreed deadline
AcknowledgmentPublished only with researcher consent
ConfidentialityReports and reporter data are access-controlled

Automated discovery

Security tools may use security.txt — RFC 9116. Human reporters should use the vulnerability reporting page.