Skip to main content
Use private vulnerability reporting. Email security@xquik.com if GitHub is unavailable. Do not open a public issue, discussion, or pull request for a vulnerability.

What to Include

Include these details when available:
  • A clear description of the issue
  • Reproduction steps and affected URLs
  • Request and response samples with secrets removed
  • The affected endpoint, SDK version, or documentation page
  • The expected impact
  • A suggested mitigation
Never send API keys, passwords, session cookies, or personal data.

Response Targets

Xquik reviews private reports against these targets:
  • Acknowledgement within 24 hours
  • Initial triage within 72 hours
  • A mitigation plan after triage
  • Progress updates at least every 14 days
Critical issues receive immediate priority.

Scope

The security contact covers:
  • docs.xquik.com
  • The Xquik REST API
  • The Xquik MCP server
  • OAuth 2.1 flows
  • Webhook signature verification
  • Published Xquik SDKs
Send product support questions to support@xquik.com.

Threat Model

Protected assets include contract integrity and release metadata. Repository changes, build inputs, links, and deployment cross trust boundaries. Tests detect public contract drift. Pinned workflows and lockfile integrity protect documentation builds.

Safe Harbor

Xquik supports good-faith security research that avoids privacy violations, data destruction, and service interruption. Allow reasonable time for remediation before public disclosure. Xquik is an independent third-party service. Not affiliated with X Corp. “Twitter” and “X” are trademarks of X Corp.