# Vulnerability Disclosure Policy

Xquik welcomes good-faith security reports for its owned services.

## Scope

- `xquik.com`
- `dashboard.xquik.com`
- `docs.xquik.com`
- Public Xquik API, webhook, OAuth, SDK, and MCP surfaces

Third-party services and customer-managed endpoints are outside scope.

## Report a Vulnerability

Email `support@xquik.com` with this subject: `Security report`.

Include the affected URL, impact, reproduction steps, and supporting evidence.
Remove secrets and unrelated personal data before sending the report.

## Research Rules

- Test only accounts, data, and systems you control.
- Avoid privacy violations, disruption, data loss, and degraded service.
- Do not use social engineering, denial of service, or high-volume automation.
- Stop testing if you encounter another person's data.
- Report the issue promptly and keep it confidential during review.

## Our Process

Xquik reviews reports and prioritizes confirmed security issues. We may request
more evidence or reproduction details. We will share material remediation
updates when possible.

Xquik does not offer a bug bounty or guaranteed payment.

## Safe Harbor

Research following this policy is authorized for Xquik-owned services. Xquik
will not pursue legal action for accidental good-faith violations. This policy
does not authorize access to third-party systems or data.

Xquik is an independent third-party service. Not affiliated with X Corp.
"Twitter" and "X" are trademarks of X Corp.
