Vulnerability Disclosure

Vulnerability Disclosure

Last updated: 8.5.2026

Qreform Oy takes the security of its services seriously. If you discover a potential security vulnerability in a Qreform-owned service, website, or system, please report it to us responsibly.

Please send reports to:

info@qreform.com

Include enough information for us to understand and verify the issue, such as the affected URL or service, a short description, and steps to reproduce the issue where possible.

When reporting a vulnerability, please do not:

  • access, copy, modify, delete, or disclose data that does not belong to you
  • disrupt or degrade our services
  • perform denial-of-service testing
  • use social engineering, phishing, or physical attacks
  • publicly disclose the issue before we have had a reasonable opportunity to review it

Qreform will review reports submitted in good faith and take appropriate action where necessary.

This is not a bug bounty program. Submitting a report does not create any right to compensation, public recognition, or any other reward.

This policy does not grant permission to conduct unlawful activity or testing that may harm Qreform, its customers, users, systems, or data.

For security-related matters, contact:

info@qreform.com