Updated

Reporting a security issue

How to report a vulnerability in Querly's website or desktop app, and what we do with your report.

If you think you have found a security vulnerability in the Querly website (getquerly.com) or the Querly desktop app, please tell us. We take every report seriously.

How to report

Email teun@getquerly.com with:

  • what you found and where (a URL, or the app version and Windows version),
  • the steps to reproduce it,
  • what an attacker could do with it, as far as you know.

Please don't include personal data of others in your report beyond what is needed to show the problem. Our machine-readable contact details are in security.txt.

What we do

  • We confirm that we received your report within three working days.
  • We investigate, keep you informed, and tell you when it is fixed.
  • We ask you to give us reasonable time to fix the issue before you make it public; we aim to fix and disclose within 90 days.
  • If you want, we credit you when we announce the fix.
  • When a vulnerability in the app is actively exploited, we report it to the authorities as the EU Cyber Resilience Act requires, and we inform the users who are affected.

Acting in good faith

If you look for and report a vulnerability in good faith, stay within what is needed to show it, don't access, change or delete other people's data, don't disrupt the service, and give us time to fix it, we won't take legal action against you for that research.

Out of scope: denial-of-service attacks, spam, social engineering or phishing of our team, physical attacks, and reports from automated scanners without a demonstrated vulnerability.

We don't run a paid bug bounty.