> ## Documentation Index
> Fetch the complete documentation index at: https://docs.xquik.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security reports for Xquik API, MCP & webhooks

> Report vulnerabilities affecting Xquik docs, API keys, REST requests, MCP, OAuth, webhooks, SDKs, account connections, or exports through a private channel.

Use [private vulnerability reporting](https://github.com/Xquik-dev/xquik-docs/security/advisories/new).

Email [support@xquik.com](mailto:support@xquik.com) with the subject `Security report` if GitHub is unavailable.

Do not open a public issue, discussion, or pull request for a vulnerability.

## What to include

Describe the issue, impact, affected URL, and reproduction steps. Include safe
request or response samples when useful. Remove every secret and personal field.

Never send API keys, passwords, session cookies, or personal data.

## Response targets

Xquik reviews private reports against these targets:

* Acknowledgement within 24 hours
* Initial triage within 72 hours
* A mitigation plan after triage
* Progress updates at least every 14 days

Critical issues receive immediate priority.

## Scope

The security contact covers Xquik docs, REST, MCP, OAuth, webhooks, and SDKs.

Send product support questions to [support@xquik.com](mailto:support@xquik.com).

## Verify bot identity

Xquik publishes Web Bot Auth keys at
`https://xquik.com/.well-known/http-message-signatures-directory`.

Require HTTPS and the documented origin. Check the `Content-Digest` header.
Verify every RFC 9421 `bindingN` signature with its Ed25519 JWK. Reject expired
keys or signatures. The JSON response never includes private key material.

Follow `Cache-Control` when caching the directory. Key rotation keeps an overlap
window so clients can refresh without losing valid signatures.

## Threat model

Protected assets include contract integrity and release metadata. Tests detect
public drift. Exact dependency pins and lockfile integrity protect documentation builds.

## Safe harbor

Xquik supports good-faith security research that avoids privacy violations, data destruction, and service interruption. Allow reasonable time for remediation before public disclosure.

Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.