QorTrace
qortrace-security-v1.0ACTIVESECURITY · DISCLOSURE · LAST UPDATED FEBRUARY 2026

Security & Responsible Disclosure

QorTrace is a cryptographic-risk product, so we hold ourselves to a high security bar. We welcome reports from the security community and commit to working in good faith with researchers who help us keep QorTrace safe.

2dACK SLA·
5dTRIAGE SLA·
24hCRITICAL FIX SLA·
1.0POLICY VERSION

Crypto-grade security bar

QorTrace is a cryptographic-risk product, so we hold ourselves higher than typical SaaS. Every admin role requires hardware-backed TOTP 2FA.

Safe harbor

We will not pursue civil or criminal action against good-faith researchers who follow this policy. We will work with you on coordinated disclosure.

Triage in 5 business days

We acknowledge reports within 2 business days and provide a triage decision within 5. Fix windows depend on severity — Critical = 24h, High = 7d, Medium = 30d.

Hall of Fame & swag

Valid, novel reports get permanent listing in our Researcher Hall of Fame on this page (with your consent). Standout reports get QorTrace-branded gear shipped worldwide.

GET STARTED IN 60s
Need to scope a PQC audit, scan a wallet, or pick a tier? I'll walk you through it in under a minute — with sources.