COORDINATED DISCLOSURE
Vulnerability Disclosure Policy
This policy defines good-faith security research, prohibited activities, handling of sensitive evidence and coordinated disclosure.
01
In scope
- quantumsafe.mobile-id.vn and explicitly listed demonstration endpoints.
- Published QuantumSafe product releases and pilot packages supplied for testing.
- API/documentation errors that create a security impact.
- Authentication, authorization, cryptographic misuse, injection, data exposure and supply-chain issues.
02
Out of scope / prohibited
- Denial-of-service, destructive or high-volume testing.
- Social engineering, phishing or physical intrusion.
- Accessing, retaining or modifying another party’s data.
- Persistence, lateral movement or credential harvesting.
- Testing production customers without written authorization.
- Publishing unredacted secrets or personal information.
03
Good-faith expectations
Use the minimum access necessary, stop when sensitive data is encountered, preserve evidence securely, allow reasonable remediation time and coordinate disclosure with PSIRT. Mobile-ID will evaluate safe-harbor language with legal counsel before production publication; this draft does not create a legal waiver.
04
Disclosure process
| Topic | Policy |
|---|---|
| Communication | Use the PSIRT tracking ID and agreed secure channel |
| Status updates | Provided based on severity and remediation complexity |
| CVE | Requested/assigned where applicable and approved |
| Public disclosure | Coordinated after mitigation or agreed deadline |
| Acknowledgment | Published only with researcher consent |
| Confidentiality | Reports and reporter data are access-controlled |
Automated discovery
Security tools may use security.txt — RFC 9116. Human reporters should use the vulnerability reporting page.
