Home/Security
§ Security

How to report an issue, and how we handle trust.

A security company should be the easiest place to report a security problem. This page covers our responsible‑disclosure contact, our posture, and how qualified parties access confidential diligence materials.

01 Posture
How the work is designed
[01]

Safe outcome by design

When trust cannot be established, the system is designed to limit exposure and fall back to a controlled, policy‑limited outcome rather than assume ordinary access should continue unchanged.

[02]

Coexist, do not replace

Built to add a defense surface alongside existing network, endpoint, identity, governance, and infrastructure investments.

[03]

Evidence over claims

Public statements stay sourced. Capability claims are reserved for verifiable review under NDA.

[04]

Disclosure discipline

Public materials stay high level. Mechanism, architecture, and claim detail are gated, not hinted at.

02 Standards & Threat Context
Sources, not self‑claims

Every factual statement in this section is attributed to its source and links out to it. Sentences about the portfolio are limited to capability categories and design targets. Nothing on this page claims a certification, an audit result, an authorization to operate, or an endorsement.

[S1]

Data‑Layer Protection

NIST SP 800‑171 Rev. 3 defines the federal baseline for protecting controlled unclassified information in nonfederal systems. The portfolio’s data‑protection families are designed to be evaluated against that baseline in NDA review. NIST SP 800‑171 r3 →

[S2]

Zero Trust Architecture

NIST SP 800‑207 defines zero trust around deny‑by‑default access and continuous verification, and CISA’s Zero Trust Maturity Model v2.0 stages its adoption. Controlled‑fallback behavior across the portfolio is a design target set against that model. NIST SP 800‑207 → CISA ZTMM v2 →

[S3]

Post‑Quantum Readiness

NIST finalized FIPS 203, 204, and 205 in August 2024, and NSA’s CNSA 2.0 sets migration expectations for national security systems. The quantum‑era families target crypto‑agility outcomes consistent with that transition. NIST PQC → NSA CNSA 2.0 →

[S4]

Adversary Behavior Mapping

MITRE ATT&CK is the shared reference for adversary tactics and techniques. Public capability categories are written so evaluators can map them to ATT&CK during confidential technical review. MITRE ATT&CK →

[S5]

Breach Evidence & Incident Response

NIST SP 800‑61 Rev. 3, finalized in April 2025, reframes incident response as continuous risk management aligned to CSF 2.0, and IBM’s Cost of a Data Breach research documents multimillion‑dollar averages with detection measured in months. The validation family targets evidence outcomes reviewable against those expectations. NIST SP 800‑61 r3 → IBM CODB →

[S6]

Identity & Synthetic‑Media Fraud

The FBI’s Internet Crime Complaint Center documents identity‑enabled fraud losses in its annual reports. Identity‑defense families target verification and consent outcomes for that documented threat class. FBI IC3 →

[S7]

Human‑Layer Risk

Verizon’s Data Breach Investigations Report has repeatedly found the human element involved in a majority of breaches. The human‑layer family addresses that category directly. Verizon DBIR →

03 Responsible Disclosure
Coordinated vulnerability disclosure

If you believe you have found a security vulnerability in a QamCrHeds website or service, we want to hear from you. We welcome good‑faith research and will work with you to understand and resolve the issue.

Report to: security@qamcrheds.com. Our machine‑readable contact is published at /.well‑known/security.txt, following RFC 9116.

What helps

A description of the issue, the steps or proof of concept needed to reproduce it, the affected URL or asset, and any thoughts on impact. Please give us reasonable time to investigate and remediate before any public disclosure, and avoid privacy violations, data destruction, or service degradation while testing.

What to expect

We acknowledge reports as quickly as we can, keep you updated as we work toward a fix, and credit researchers who wish to be named once an issue is resolved. This is a coordinated‑disclosure process, not a paid bug‑bounty program at this stage, and good‑faith reports are always welcome.

Preferred languages: English.

04 Trust & Diligence
Materials available under NDA

QamCrHeds keeps a clear line between public and confidential. Public materials describe the market gap and high‑level capability areas. Confidential materials, including proof‑of‑concept demonstrations, architecture overviews, and IP diligence, are shared with qualified investors, grant reviewers, and pilot partners under a signed non‑disclosure agreement.

Compliance roadmap. Framework references across the portfolio (for example NIST, CMMC, HIPAA, FedRAMP, and Zero Trust) indicate potential relevance to regulated environments and control‑mapping discussions. They are stated as goals and design considerations, not as certifications, audits, authorizations to operate, or endorsements.