How to report
Email editor@qaeda.org with the affected URL, a concise description, reproducible evidence that does not expose private data, and the impact you believe the issue could have.
Testing boundaries
- Do not access, alter, retain, or publish other people’s private data.
- Do not use denial-of-service, destructive payloads, persistence, social engineering, credential stuffing, or spam.
- Do not test third-party systems merely because QAEDA links to them.
- Stop when you have enough evidence to demonstrate the issue safely.
Scope
The public QAEDA.org application and its deployment configuration are the intended scope of this policy. AL.QAEDA.ORG is a related subdomain with its own published scope and should not be assumed to share this policy unless it says so.
What to expect
This project does not currently advertise a bug-bounty or payment program. A report should be judged on technical evidence and user impact rather than on public pressure. Security fixes may require hosting-provider or deployment-level changes that are outside the repository itself.
Machine-readable contact
The canonical security contact file is available at /.well-known/security.txt.