Security
Reporting a vulnerability, or a defect in the content credentials we issue
Write to us at
security@qamera.ai
Please include enough for us to reproduce what you found: the file, the steps you took, and what you expected instead.
This address stays published for as long as Qamera AI is listed on the C2PA Conforming Products List.
What to report here
- A malformed or invalid content-credentials manifest in a file Qamera AI produced.
- An exported file that left without the signature it should carry.
- A manifest claim that does not match what we actually did to the image.
- A security vulnerability in the platform, its API, or its plugins.
What belongs to the other channel
Reports that generated content depicts a real person, or is otherwise prohibited, go to our AI Act Article 5 reporting channel, not here. Its address is behind the "Report a violation" entry in the footer below, and it is stated in § 12.4 of the Terms of Service.
The two are kept apart on purpose: a report about a defective manifest that lands in a mailbox described as taking misuse reports is triaged as the wrong kind of thing, and whoever wrote it is given no signal that it went to the wrong place.
Machine-readable contact
The same contact is published in the format of RFC 9116 at:
/.well-known/security.txt