Never include Xquik API keys or credentials in issues, pull requests, examples, logs, or tests.
Report vulnerabilities through GitHub private vulnerability reporting. If that form is unavailable, email support@xquik.com.
Do not publish exploit details, secrets, or private data in an issue.
Expect an acknowledgment within 3 business days. We will set a disclosure timeline after we confirm the issue.
Security fixes target the latest published release.