What to include
Describe the issue, impact, affected URL, and reproduction steps. Include safe request or response samples when useful. Remove every secret and personal field. Never send API keys, passwords, session cookies, or personal data.Response targets
Xquik reviews private reports against these targets:- Acknowledgement within 24 hours
- Initial triage within 72 hours
- A mitigation plan after triage
- Progress updates at least every 14 days
Scope
The security contact covers Xquik docs, REST, MCP, OAuth, webhooks, and SDKs. Send product support questions to support@xquik.com.Verify bot identity
Xquik publishes Web Bot Auth keys athttps://xquik.com/.well-known/http-message-signatures-directory.
Require HTTPS and the documented origin. Check the Content-Digest header.
Verify every RFC 9421 bindingN signature with its Ed25519 JWK. Reject expired
keys or signatures. The JSON response never includes private key material.
Follow Cache-Control when caching the directory. Key rotation keeps an overlap
window so clients can refresh without losing valid signatures.