Skip to content

Security: quikbot/quiksync

SECURITY.md

Security Policy

QuikSync governs physical action across shared spaces, machines, and people. A security issue here can have consequences that a purely digital system does not, and we treat reports accordingly.

Reporting a vulnerability

Do not open a public issue for a security report.

Two channels, in order of preference:

  1. GitHub private vulnerability reporting — use the Report a vulnerability button under this repository's Security tab. This keeps the report private between you and us until a fix is available.
  2. Emailtech@quikbot.ai with SECURITY in the subject line.

Please include, as far as you can:

  • what the issue is, and the impact you believe it has;
  • the affected surface — a QuikSync deployment host, a published connector or adapter, a documented API, or this repository's contents;
  • reproduction steps or a proof of concept;
  • any deployment details that matter (version, environment, connector types).

What to expect

Acknowledgement Within 3 business days.
Initial assessment Within 10 business days, including our severity view and whether we can reproduce it.
Progress updates At least every 14 days until the report is resolved or closed.
Disclosure Coordinated. We will agree a disclosure timeline with you, and we will credit you when a fix ships unless you prefer otherwise.

Scope

In scope — the QuikSync platform and its deployed services, published connectors and adapters (including open-rmf-adapters-quiksync), documented APIs, and the contents of this repository.

Out of scope — third-party robot fleets, building systems, and vendor software that QuikSync integrates with. Report those to their vendor; tell us too if the interaction with QuikSync is what creates the risk.

Please do not test against a production deployment you do not own, disrupt a live operation, or access data belonging to another organisation. If you believe a finding needs live validation, contact us first and we will arrange a safe environment.

We do not currently run a paid bug bounty. We do acknowledge and credit every valid report.

There aren't any published security advisories