How to report it

Write to info@quince-ai.com with "Security" in the subject line. Tell us what you found, where, and the steps to reproduce it. A screenshot or a request and response helps. Write in Swedish or English.

Please do not put the details in a public issue, a social media post or a support chat, and do not include other people's data in the report.

What we do

  • An engineer reads every report and replies to the address you wrote from.
  • We tell you whether we can reproduce the problem, and when it is fixed.
  • If you want credit, we name you when we describe the fix.

Acting in good faith

If you look only as far as you need to show the problem, do not read, change or delete other people's data, do not disrupt the service, and give us reasonable time to fix it before you publish, we will not report you to the police or take legal action against you.

What is in scope

  • The website at quince-ai.com and its forms
  • Egen workspaces we run for customers

Out of scope: attacks that overload the service, social engineering of our staff or customers, physical attacks, and weaknesses in third-party services that we do not run.

How Egen handles your data

Where Egen keeps data, who can reach it and which rules it answers to is on the Egen page: the rules and what Egen keeps.

Machine-readable contact details are in /.well-known/security.txt. Last updated .