Security

Tell us quietly. We will act.

This is the reporting and coordinated-disclosure policy for Quietmill. Product-specific architecture and controls are linked below.

Report a vulnerability

Email [email protected]

Include the affected product or page, what you observed and the smallest safe set of steps that reproduces it. Please do not send passwords, live access tokens, customer records or other people's personal data. Do not open a public issue for a suspected vulnerability.

What happens next

  • We aim to acknowledge reports within one business day, Monday to Friday, 09:00–17:00 UK time.
  • We investigate, keep the reporter informed and prioritise a confirmed security fix.
  • We support coordinated disclosure and ask for reasonable time to protect users before technical details are published.
  • If a confirmed incident affects customer data, we notify affected customers through the relevant product and support channels without undue delay.

Last reviewed: 4 August 2026.

Product security

Security follows the product

Approval Nudge

The Jira app runs inside Atlassian's hosted app platform and does not send customer data to Quietmill infrastructure. Its product security page explains the data boundary and controls.

Read the Approval Nudge security policy →

Donne du jour

Players can choose whether to share future completed games for AI improvement. Shared games pass strict validation and carry no name, account or stable player identifier. The product privacy policy explains the data boundary and retention.

Read the Donne du jour privacy policy →

Security tells you how to report a problem. Privacy tells you what each product handles in normal use.