Skip to content

Vulnerability Disclosure Policy

How to report a suspected voiqq security issue safely and in good faith.

voiqq welcomes good-faith reports that help protect users. This policy does not authorize testing of customer projects, public-share targets, third-party providers, or infrastructure you do not own.

How to report

Email admin@voiqq.com with the affected URL or feature, reproduction steps, impact, relevant request identifiers, and a safe proof of concept. Remove personal data and secret values. Encrypt sensitive coordination where mutually arranged.

Good-faith boundaries

  • Use accounts and workspaces you own or are authorized to test
  • Stop when you encounter another person's data and report the boundary
  • Use the minimum requests and data needed to demonstrate the issue
  • Allow reasonable remediation time before disclosure
  • Comply with law and do not demand payment or threaten disclosure

Prohibited testing

  • Denial of service, load testing, spam, or social engineering
  • Destructive actions, persistence, malware, or data exfiltration
  • Testing Paddle, Supabase, Vercel, Resend, Cloudflare, Google, Groq, or customer systems under this policy
  • Automated scanning that creates material traffic or records without prior written permission

Our response

We aim to acknowledge actionable reports, investigate, communicate material progress, and remediate according to risk. If you follow this policy, voiqq will treat the research as authorized to the extent we can, will not pursue action for accidental good-faith violations, and will work with you to resolve ambiguity.

voiqq Vulnerability Disclosure Policy