Security is designed with the system
We describe only controls that can be substantiated. Certifications or compliance levels are not claimed without completed independent assessment.
updated: 13.07.2026
baseline controls
Protecting the public surface
qdev.run uses HTTPS, restricted system permissions, an isolated intake service, and data minimization.
- secrets are not stored in the repository or client-side JavaScript
- the form limits request size and frequency
- the operational database is not exposed to the public network
delivery
Changes are checked before release
Releases cover syntax, routes, local resources, interfaces, and the actual production state.
- dependency and accidental-secret checks
- automated and browser checks for critical flows
- backup and reproducible rollback before runtime changes
disclosure
How to report a vulnerability
Do not publish details before receipt is confirmed. We will agree on a safe channel for sensitive material.
- channel: hello@qdev.run
- include the affected URL, reproduction steps, and potential impact
- do not access third-party data or disrupt service availability
Found a security issue?
Send the smallest reproducible description. Share confidential material only after a channel is agreed.
report securely ->