Report a vulnerability privately
The current reporting route is a Qalbii support ticket. Ticket submission requires a signed-in Qalbii member account; the ticket and its status are not public. Choose Technical issue and begin the subject with Security vulnerability: so it can be triaged correctly.
Open the private ticket routeAnonymous reporting is not currently available. Qalbii does not yet operate a monitored anonymous disclosure mailbox or public anonymous security-report form. If you cannot use the signed-in ticket route, do not post vulnerability details in public issues, social media, or community channels. Keep evidence securely until an anonymous channel is published here.
What to include
Give us enough information to reproduce and assess the issue without collecting extra member data.
- The affected Qalbii page, API route, app version, or feature.
- Clear reproduction steps, the observed result, and the security impact.
- The date and time of testing, including the relevant time zone.
- Minimal, sanitised screenshots or request details where they are necessary.
Redact passwords, MFA codes, session cookies, authorisation headers, private keys, payment data, and identity documents. If you encounter another person's data, stop testing and do not copy, retain, alter, or share it.
Research boundaries
This policy covers Qalbii systems that Qalbii owns and operates, including the web application serving this page and its application API. Third-party products and infrastructure are outside scope.
- Use only accounts and data you own or have explicit permission to test.
- Keep automated traffic low-volume and stop if service stability may be affected.
- Do not use denial of service, spam, social engineering, physical intrusion, or destructive testing.
- Do not change, delete, download, or disclose member data, and do not weaken another person’s privacy.
Good-faith research and safe harbour
Qalbii will treat research that follows this policy, is performed in good faith, and is reported promptly through the route above as authorised for the purposes of applicable anti-hacking law. Qalbii will not initiate legal action solely because of that compliant research. This does not authorise unlawful conduct or testing of third-party systems. If you are unsure whether an action is permitted, stop and report what you have found before continuing.
After you report
The support flow provides a ticket reference immediately. Signed-in reporters can use the support centre to view its status. We may ask for clarification or a safe retest. Please allow reasonable time for investigation and remediation before public disclosure. This programme does not promise a payment or bounty unless Qalbii agrees to one in writing.