Report a security vulnerability
This page is the designated contact point for reporting security vulnerabilities in KEEQuant products, in line with our obligations under Article 14 of the EU Cyber Resilience Act. Reports are handled by our Product Security Incident Response Team (PSIRT).
We acknowledge every report within 3 business days and aim to provide an initial assessment within 14 days. This mailbox is for vulnerability reports only — for general inquiries, please use info@keequant.com.
Encrypt your report
Use the PGP key below if your report involves an unpatched vulnerability. Optional, but recommended for anything not yet public.
Describe the issue
Affected product and firmware/software version, a description of the vulnerability, and its potential impact.
Include reproduction details
Steps to reproduce, proof-of-concept, logs, or traffic captures — whatever lets us confirm the issue without guessing.
Give us time to respond
We follow coordinated disclosure. We’ll agree a disclosure timeline with you once the report is confirmed.
Encrypted Reporting — PGP
Our Commitment
We investigate every report in good faith and will not pursue legal action against researchers who report vulnerabilities responsibly under this policy and avoid privacy violations, data destruction, or service disruption. We ask that you keep details confidential until we have released a fix or mutually agreed on a disclosure date, consistent with our coordinated vulnerability disclosure obligations under the Cyber Resilience Act.