generated: '2026-08-26' method: searched source: https://www.qualified.com/trust disclosure_channel_published: true policy_name: Responsible Disclosure Policy policy_url: https://www.qualified.com/trust policy_text_public: false contact: email: security@qualified.com source: https://www.qualified.com/trust note: >- Published on the trust page behind Cloudflare email obfuscation; decoded from the page's own data-cfemail attribute, so it is a real published address and not inferred. security_txt: served: false probed: - url: https://www.qualified.com/.well-known/security.txt status: 404 - url: https://api.qualified.com/.well-known/security.txt status: 404 - url: https://app.qualified.com/.well-known/security.txt status: 403 note: Cloudflare bot challenge, not a document bug_bounty: program: null platform: null note: >- No HackerOne, Bugcrowd, Intigriti or self-hosted bounty program was found. Searched the trust center and the site; none is advertised. safe_harbor: stated: false note: >- A "Responsible Disclosure Policy" is named in the trust center's policy inventory, but the policy text — and therefore any safe-harbour language, scope statement or response SLA — is only released under NDA. A researcher can find an address to write to; they cannot read the terms they would be disclosing under. Recorded as a real but thin disclosure surface. adjacent_controls: - name: Vulnerability Management Policy public: name only - name: Incident Response Plan public: name only - name: Annual third-party black-box penetration testing public: described on the trust page gaps_for_provider: - Publish /.well-known/security.txt (RFC 9116) on www.qualified.com and api.qualified.com naming security@qualified.com and a Policy URL. - Publish the Responsible Disclosure Policy text itself, including scope and safe harbour, outside the NDA-gated Trust Center.