trust / security

Security is designed with the system

We describe only controls that can be substantiated. Certifications or compliance levels are not claimed without completed independent assessment.

updated: 13.07.2026

baseline controls

Protecting the public surface

qdev.run uses HTTPS, restricted system permissions, an isolated intake service, and data minimization.

  • secrets are not stored in the repository or client-side JavaScript
  • the form limits request size and frequency
  • the operational database is not exposed to the public network
delivery

Changes are checked before release

Releases cover syntax, routes, local resources, interfaces, and the actual production state.

  • dependency and accidental-secret checks
  • automated and browser checks for critical flows
  • backup and reproducible rollback before runtime changes
disclosure

How to report a vulnerability

Do not publish details before receipt is confirmed. We will agree on a safe channel for sensitive material.

  • channel: hello@qdev.run
  • include the affected URL, reproduction steps, and potential impact
  • do not access third-party data or disrupt service availability
Found a security issue?

Send the smallest reproducible description. Share confidential material only after a channel is agreed.

report securely ->