Safe Harbor Guarantee: FQRS will not pursue legal action against security researchers who conduct research in good faith, adhere to this Responsible Disclosure Policy, and refrain from compromising user data or disrupting live production infrastructure.
1. Commitment to Community Security
At FQRS (Forensic Quality Reporting Solutions), we recognize the vital role that independent ethical hackers, bug bounty researchers, and cybersecurity engineers play in securing the digital ecosystem. We encourage responsible submission of security vulnerabilities found in FQRS digital assets or managed infrastructure.
2. Guidelines for Ethical Research
Researchers participating in our disclosure program must abide by the following guidelines:
- No User Data Access: Do not access, modify, download, or delete user data or client confidential information. If you stumble upon sensitive data, stop testing immediately and report it.
- No Service Disruption: Do not execute Denial of Service (DoS/DDoS), spam attacks, social engineering, or physical security attacks against staff or servers.
- Coordinated Disclosure: Allow FQRS a reasonable window (typically 30-60 days) to patch the vulnerability before making details public.
3. Program Scope
In-Scope Assets:
- Website domain:
www.fqrs.co.inand subdomains. - Official FQRS web applications & public APIs.
Out-of-Scope (Prohibited):
- Third-party services or client systems audited by FQRS (unless authorized under client-specific bug bounties).
- Partner applications (such as Sales Funda®) which have dedicated, isolated reporting channels.
- Phishing, social engineering, or physical intrusion attempts.
4. Triage SLA & Recognition (Hall of Fame)
When you report a valid, unique, and actionable vulnerability to FQRS:
- Acknowledgement: Receipt confirmation within 24 hours.
- Triage & Validation: Technical assessment and severity rating (CVSS v3.1) within 48 hours.
- Recognition: Valid disclosures qualify for formal Certificate of Recognition and inclusion on our official Track Record & Hall of Fame page.
5. How to Submit a Vulnerability Report
Please submit your findings directly to our Security Operations Desk with clear steps to reproduce, HTTP requests/responses, and potential impact assessment:
FQRS Security Response Team
Email: [email protected]
Subject Line Format: [Vulnerability Report] Impacted Asset - Bug Type