Skip to content

Vulnerability Disclosure

XBert welcomes reports of suspected security vulnerabilities from the security research community, customers, and the public. We will work in good faith with anyone who reports a vulnerability responsibly.

Send your report to security@xbert.io with as much of the following information as possible:

  1. A description of the vulnerability
  2. The affected URL, endpoint, or product surface
  3. Steps to reproduce, including any proof-of-concept code or screenshots
  4. Your assessment of the impact
  5. Your name and a contact channel — we will acknowledge your report and may need to ask follow-up questions

You may report anonymously, but providing contact details allows us to acknowledge your work, ask clarifying questions, and confirm remediation.

Reports against the following are in scope:

  • *.xbert.io web properties (including app.xbert.io, trust.xbert.io, support.xbert.io, mcp-gateway.xbert.io)
  • The XBert Public API
  • XBert mobile applications

The following are out of scope:

  • Third-party services that XBert integrates with (Xero, QuickBooks, MYOB, FreeAgent, Auth0, Chargebee, Stripe, Intercom, etc.) — please report directly to the relevant provider
  • Social-engineering, phishing, or physical attacks against XBert staff or facilities
  • Denial-of-service testing
  • Findings from automated scanners without a demonstrated security impact
  • Missing best-practice headers without a demonstrated exploit
  • Outdated software versions without a demonstrated exploit
  • Self-XSS or vulnerabilities requiring an attacker to control the victim’s device

If you report in good faith and follow this policy, XBert will:

  • Not pursue or support legal action against you for accessing or attempting to access XBert systems for the purpose of reporting the vulnerability, provided you stay within the testing limits below
  • Work with you to understand and resolve the issue
  • Recognise your contribution publicly if you wish (with your permission)

Testing limits:

  • Do not access, modify, or delete data belonging to other users
  • Do not exfiltrate any data — stop at proof-of-concept
  • Do not perform testing that degrades service for other users
  • Use test accounts where possible
StageTarget
Acknowledgement of reportWithin 3 business days
Initial triage and severity assessmentWithin 5 business days
Remediation — CriticalWithin 48 hours
Remediation — HighWithin 7 days
Remediation — MediumWithin 30 days
Remediation — LowWithin 90 days
Disclosure to reporter on remediationAt time of fix release

Severity is assessed against the affected data classification (Confidential / Internal / Public), exploitability, and exposure. XBert uses the CVSS v3.1 framework as a guide.

  • XBert does not operate a paid bug bounty programme at this time. Recognition is via acknowledgement only.
  • XBert will not threaten or pursue researchers who report in good faith under this policy.

For sensitive reports, you may request our PGP key by emailing security@xbert.io. We will respond with the current key fingerprint.

VersionDateChange
1.02026-06-04Initial publication