Skip to main content
Use private vulnerability reporting. Email security@xquik.com if GitHub is unavailable. Do not open a public issue, discussion, or pull request for a vulnerability.

What to include

Describe the issue, impact, affected URL, and reproduction steps. Include safe request or response samples when useful. Remove every secret and personal field. Never send API keys, passwords, session cookies, or personal data.

Response targets

Xquik reviews private reports against these targets:
  • Acknowledgement within 24 hours
  • Initial triage within 72 hours
  • A mitigation plan after triage
  • Progress updates at least every 14 days
Critical issues receive immediate priority.

Scope

The security contact covers Xquik docs, REST, MCP, OAuth, webhooks, and SDKs. Send product support questions to support@xquik.com.

Verify bot identity

Xquik publishes Web Bot Auth keys at https://xquik.com/.well-known/http-message-signatures-directory. Require HTTPS and the documented origin. Check the Content-Digest header. Verify every RFC 9421 bindingN signature with its Ed25519 JWK. Reject expired keys or signatures. The JSON response never includes private key material. Follow Cache-Control when caching the directory. Key rotation keeps an overlap window so clients can refresh without losing valid signatures.

Threat model

Protected assets include contract integrity and release metadata. Tests detect public drift. Pinned workflows and lockfile integrity protect documentation builds.

Safe harbor

Xquik supports good-faith security research that avoids privacy violations, data destruction, and service interruption. Allow reasonable time for remediation before public disclosure. Xquik is an independent third-party service. Not affiliated with X Corp. “Twitter” and “X” are trademarks of X Corp.