Responsible disclosure
If you believe you have found a security vulnerability in our website, our apps, or our platform, we want to hear about it — and we will not pursue good-faith research.
1. Scope
This policy covers the corporate website at quantum-digital.tech, our subscription products (Games Empire, FlexiFit VIP, Savora), and the public-facing surfaces of the Quantum Rail platform. Operator and gateway systems we integrate with are out of scope — they belong to our partners, and testing them without authorisation may be unlawful.
2. How to report
Email [email protected]with “Security” in the subject line. Include what you found, where, the steps to reproduce it, and its potential impact. We acknowledge reports within five business days and keep you informed as we validate and fix. A machine-readable version of this policy lives at /.well-known/security.txt.
3. Ground rules
- Do not access, modify, or exfiltrate data that is not yours. If you encounter personal data, stop and report immediately.
- No denial-of-service testing, spam, or social engineering of our staff or partners.
- Do not degrade the service for real subscribers.
- Give us reasonable time to remediate before any public disclosure.
4. What you can expect from us
- We will not pursue legal action against research conducted in good faith within this policy.
- We will confirm receipt, keep you updated, and credit you in the fix notes if you want credit.
- We do not operate a paid bug bounty at this time. If that changes, this page will say so.
Last updated · August 2026