Vulnerability Disclosure Policy
SoftTelRG LLC welcomes good-faith security research on WebSureQTool and its public websites. If you believe you have found a vulnerability, we want to hear from you — this page explains what is in scope, how to report, and what you can expect from us.
Last updated: August 21, 2026
How to report
Report suspected vulnerabilities through our contact form with “Security” in the subject, or via the contact address published in our security.txt. Please include:
- A description of the issue and where it was found (product version or URL).
- Steps to reproduce — a minimal proof of concept is ideal.
- The potential impact, as you understand it.
- How we can reach you for follow-up (email is fine; anonymous reports are accepted).
What to expect from us
- Acknowledgment within 3 business days of receiving your report.
- An assessment and expected timeline within 10 business days — we will tell you whether we can reproduce the issue and how we plan to address it.
- A fix or mitigation as quickly as severity warrants. Desktop fixes ship through the Microsoft Store update channel; website fixes deploy directly.
- Credit, if you want it. With your permission, we are happy to acknowledge your report once the issue is resolved. We do not currently operate a paid bounty program.
- Coordinated disclosure. We ask that you give us a reasonable window to remediate before public disclosure; we will work with you on timing and keep you informed.
In scope
- The WebSureQTool desktop application (current Microsoft Store release).
- websureqtool.com and its subdomains.
- The public practice labs: wsqdemo.com and api.wsqdemo.com.
- Our account, subscription, and checkout flows on these properties.
Out of scope
- Denial-of-service, load, or volumetric testing against any of our properties, including the practice labs.
- Social engineering, phishing, or physical attacks against SoftTelRG or its users.
- Third-party services we rely on (Microsoft Store, Stripe, hosting providers) — please report issues in those platforms to their own programs.
- Findings that require a compromised device or stolen credentials as a precondition.
- Reports from automated scanners without a demonstrated, reproducible impact.
Safe harbor
We will not pursue or support legal action against researchers who, in good faith: access only the minimum data necessary to demonstrate an issue; avoid privacy violations, data destruction, and service degradation; do not access, modify, or retain data belonging to other users; and give us a reasonable opportunity to remediate before any public disclosure. Research conducted consistently with this policy is considered authorized under applicable anti-hacking and anti-circumvention laws to the extent we can authorize it. If a third party pursues action against you for activity conducted in accordance with this policy, we will make it known that your actions were authorized by us.
Because WebSureQTool executes locally, most product data (test suites, datasets, run results) never reaches our infrastructure — testing against your own local workspace requires no authorization from us at all.

