Vulnerability Disclosure
XBert welcomes reports of suspected security vulnerabilities from the security research community, customers, and the public. We will work in good faith with anyone who reports a vulnerability responsibly.
1. How to report
Section titled “1. How to report”Send your report to security@xbert.io with as much of the following information as possible:
- A description of the vulnerability
- The affected URL, endpoint, or product surface
- Steps to reproduce, including any proof-of-concept code or screenshots
- Your assessment of the impact
- Your name and a contact channel — we will acknowledge your report and may need to ask follow-up questions
You may report anonymously, but providing contact details allows us to acknowledge your work, ask clarifying questions, and confirm remediation.
2. Scope
Section titled “2. Scope”Reports against the following are in scope:
*.xbert.ioweb properties (includingapp.xbert.io,trust.xbert.io,support.xbert.io,mcp-gateway.xbert.io)- The XBert Public API
- XBert mobile applications
The following are out of scope:
- Third-party services that XBert integrates with (Xero, QuickBooks, MYOB, FreeAgent, Auth0, Chargebee, Stripe, Intercom, etc.) — please report directly to the relevant provider
- Social-engineering, phishing, or physical attacks against XBert staff or facilities
- Denial-of-service testing
- Findings from automated scanners without a demonstrated security impact
- Missing best-practice headers without a demonstrated exploit
- Outdated software versions without a demonstrated exploit
- Self-XSS or vulnerabilities requiring an attacker to control the victim’s device
3. Safe-harbour commitment
Section titled “3. Safe-harbour commitment”If you report in good faith and follow this policy, XBert will:
- Not pursue or support legal action against you for accessing or attempting to access XBert systems for the purpose of reporting the vulnerability, provided you stay within the testing limits below
- Work with you to understand and resolve the issue
- Recognise your contribution publicly if you wish (with your permission)
Testing limits:
- Do not access, modify, or delete data belonging to other users
- Do not exfiltrate any data — stop at proof-of-concept
- Do not perform testing that degrades service for other users
- Use test accounts where possible
4. Response process and SLAs
Section titled “4. Response process and SLAs”| Stage | Target |
|---|---|
| Acknowledgement of report | Within 3 business days |
| Initial triage and severity assessment | Within 5 business days |
| Remediation — Critical | Within 48 hours |
| Remediation — High | Within 7 days |
| Remediation — Medium | Within 30 days |
| Remediation — Low | Within 90 days |
| Disclosure to reporter on remediation | At time of fix release |
Severity is assessed against the affected data classification (Confidential / Internal / Public), exploitability, and exposure. XBert uses the CVSS v3.1 framework as a guide.
5. What XBert will not do
Section titled “5. What XBert will not do”- XBert does not operate a paid bug bounty programme at this time. Recognition is via acknowledgement only.
- XBert will not threaten or pursue researchers who report in good faith under this policy.
6. Encryption
Section titled “6. Encryption”For sensitive reports, you may request our PGP key by emailing security@xbert.io. We will respond with the current key fingerprint.
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026-06-04 | Initial publication |