Security & TrustLast updated: October 2026

Security Vulnerability & Responsible Disclosure Policy

Guidelines and safe-harbor principles for security researchers and network engineers reporting potential vulnerabilities to QC NetCore.

Key Compliance Highlights
  • Welcomes good-faith vulnerability reports from security researchers and ISP network engineers.
  • Provides direct reporting channels via quantumcode7777@gmail.com and WhatsApp 0712052104.
  • Establishes clear rules of engagement to protect live ISP tenants and subscriber connectivity during security research.

Section 1Our Commitment to Coordinated Vulnerability Disclosure

At QC NetCore, we value the work of independent security researchers, ethical hackers, and network engineers who help keep ISP infrastructure secure. If you discover a potential security vulnerability in the QC NetCore web application, APIs, captive portal engine, or authentication workflows, we encourage you to report it to us responsibly.

Section 2How to Submit a Vulnerability Report

Please send a detailed technical report to our Security & Engineering team via one of our verified channels:

  • Security Email: quantumcode7777@gmail.com (Subject line: 'SECURITY DISCLOSURE — QC NetCore')
  • Urgent Security Escalation (WhatsApp): 0712052104 (+254 712 052 104)
  • Include: Affected URL/endpoint, step-by-step reproduction instructions, proof-of-concept (PoC) screenshots or HTTP requests, and potential security impact.

Section 3Rules of Engagement & Good-Faith Safe Harbor

When conducting security research against QC NetCore, you must adhere to the following rules to qualify as good-faith research:

  • Use Demo Mode or your own test account: Never attempt to access, modify, or exfiltrate data belonging to third-party ISP tenants or live broadband subscribers.
  • No Service Disruption: Do not perform Denial-of-Service (DoS/DDoS) testing, automated high-volume fuzzing, or spam M-Pesa STK Push endpoints.
  • No Social Engineering or Physical Testing: Do not phish ISP staff or attempt unauthorized access to physical telecommunications cabinets or routers.
  • Confidentiality Until Remediation: Allow our engineering team a reasonable timeframe to investigate and deploy a patch before publicly disclosing any details of the finding.

Section 4What You Can Expect From QC NetCore

When you submit a report in accordance with this policy, our engineering team will acknowledge receipt, validate the finding, prioritize remediation based on severity, and notify you once the fix has been deployed to production. We will not pursue legal action against researchers who strictly follow these good-faith guidelines.

Questions About This Policy or Compliance Verification?

Reach our legal, privacy, billing, and security engineering desk directly via email or WhatsApp.