Vulnerability disclosure policy

If you believe you have found a security vulnerability in XValue, we want to hear about it. This page sets out how to report one and what happens next.

How to report

Email [email protected] with a description of the issue, the steps needed to reproduce it, and the impact you believe it has. Please include the URL or endpoint affected. Reports in English or Arabic are both welcome.

Scope

xvalue.space and api.xvalue.space are in scope, along with the mobile and web clients that talk to them. Non-production hosts, third-party services we integrate with, and findings that require physical access to a user's device are out of scope.

Testing rules

Please do not run automated scanners against production, do not attempt denial of service, and do not access, modify or delete data belonging to anyone but yourself. Use your own test account. If you access another party's data accidentally, stop, and tell us what you saw so we can assess the exposure.

What to expect

We aim to acknowledge a report within three business days and to give an assessment within ten. We will tell you when the issue is fixed. We do not currently run a paid bounty programme, and we will not pursue legal action against researchers who follow this policy in good faith.

Security Vulnerability Disclosure Policy | XValue