generated: '2026-08-26' method: searched probe: true source: https://qolab.ai/vulnerability-disclosure program: name: Vulnerability disclosure program url: https://qolab.ai/vulnerability-disclosure http_status: 200 type: coordinated-vulnerability-disclosure bug_bounty: false bounty_note: >- No bounty or reward is offered or mentioned. Qolab cites HackerOne's published standards documents but does NOT run a HackerOne program page — https://hackerone.com/qolab and https://hackerone.com/qolab_ai both returned 404 when probed on 2026-08-26. intake: method: web-form label: Submit report note: >- The page states the report form redirects to "our secure external application system (Gusto)". There is no published security@ mailbox and no PGP key. The general company contact address on every page footer is contact@qolab.ai. safe_harbor: true scope: open response_sla: null pgp_key: null security_txt: false security_txt_note: >- https://qolab.ai/.well-known/security.txt returned 404 (the Webflow host answers every /.well-known/* path with an "Invalid .well-known request" HTML stub), so the program is discoverable only from the site footer, not from RFC 9116. standards_cited: - name: Coordinated Vulnerability Disclosure url: https://www.hackerone.com/disclosure-guidelines - name: Safe Harbor (HackerOne Gold Standard Safe Harbor Statement) url: https://docs.hackerone.com/en/articles/8494525-gold-standard-safe-harbor-statement - name: Open Scope url: https://docs.hackerone.com/en/articles/8490833-security-page#h_46a5b35ded - name: Core Ineligible Findings url: https://docs.hackerone.com/en/articles/8494488-core-ineligible-findings - name: Detailed Platform Standards url: https://docs.hackerone.com/en/articles/8369826-detailed-platform-standards quote: >- "We value the contributions of the security research community and recognize the importance of a coordinated approach to vulnerability disclosure. If you have discovered a security vulnerability, we encourage you to let us know immediately. We welcome the opportunity to work with you to resolve the issue promptly." evidence: - source: https://qolab.ai/vulnerability-disclosure http_status: 200 kind: disclosure page fetched: '2026-08-26' keywords: - vulnerability - security research - hackerone - safe harbor - coordinated disclosure - source: https://hackerone.com/qolab http_status: 404 kind: bug bounty program probe (negative) fetched: '2026-08-26' - source: https://qolab.ai/.well-known/security.txt http_status: 404 kind: RFC 9116 probe (negative) fetched: '2026-08-26'