QuikSync governs physical action across shared spaces, machines, and people. A security issue here can have consequences that a purely digital system does not, and we treat reports accordingly.
Do not open a public issue for a security report.
Two channels, in order of preference:
- GitHub private vulnerability reporting — use the Report a vulnerability button under this repository's Security tab. This keeps the report private between you and us until a fix is available.
- Email — tech@quikbot.ai with
SECURITYin the subject line.
Please include, as far as you can:
- what the issue is, and the impact you believe it has;
- the affected surface — a QuikSync deployment host, a published connector or adapter, a documented API, or this repository's contents;
- reproduction steps or a proof of concept;
- any deployment details that matter (version, environment, connector types).
| Acknowledgement | Within 3 business days. |
| Initial assessment | Within 10 business days, including our severity view and whether we can reproduce it. |
| Progress updates | At least every 14 days until the report is resolved or closed. |
| Disclosure | Coordinated. We will agree a disclosure timeline with you, and we will credit you when a fix ships unless you prefer otherwise. |
In scope — the QuikSync platform and its deployed services, published
connectors and adapters (including
open-rmf-adapters-quiksync),
documented APIs, and the contents of this repository.
Out of scope — third-party robot fleets, building systems, and vendor software that QuikSync integrates with. Report those to their vendor; tell us too if the interaction with QuikSync is what creates the risk.
Please do not test against a production deployment you do not own, disrupt a live operation, or access data belonging to another organisation. If you believe a finding needs live validation, contact us first and we will arrange a safe environment.
We do not currently run a paid bug bounty. We do acknowledge and credit every valid report.