Security at Quodra
Effective September 30, 2026Last updated September 30, 2026
How to report a security issue to Quodra, how to test responsibly, and what happens after a report.
Security is an important part of how we build Quodra. We work to protect user accounts, workspaces, documents, integrations, and the infrastructure that powers the platform.
Reporting a security issue#
If you believe you have found a security vulnerability in Quodra, please contact us at security@quodra.app.
Please include, where possible:
- A description of the issue and its potential impact
- The affected feature, URL, API, or integration
- Steps we can use to reproduce the issue
- Screenshots, logs, or proof-of-concept information that may help us investigate
- Your preferred contact information for follow-up
Please do not include sensitive user information unless it is necessary to explain the vulnerability.
Responsible testing#
When investigating a potential vulnerability, please:
- Only access accounts, workspaces, and data that you own or have permission to use
- Avoid actions that could disrupt Quodra or degrade availability for other users
- Do not perform denial-of-service testing, spam, social engineering, or destructive testing
- Stop testing and contact us if you unexpectedly gain access to another user's data
- Give us reasonable time to investigate and address a vulnerability before publicly disclosing it
What happens after a report#
We will review security reports and work to understand their severity, impact, and appropriate remediation.
We aim to acknowledge legitimate security reports within a few business days and may contact you for additional information while investigating.
Quodra does not currently operate a paid bug bounty program. We nevertheless welcome responsible reports from security researchers and users.
Security questions#
For security-related questions or vulnerability reports, contact:
security@quodra.app
For general product or support questions, please use Quodra's normal support channels.