Skip to main content

Vulnerability Disclosure Policy

Last updated: July 2, 2026

Portfoliq welcomes reports from security researchers and the public about potential vulnerabilities in our services. This policy explains how to report an issue and what to expect in return.

How to report

Email security@portfoliq.ai with a description of the issue, the steps to reproduce it, and any supporting material (proof-of-concept, screenshots, logs). Please give us a reasonable opportunity to investigate and remediate before any public disclosure.

Scope

In scope: portfoliq.ai and app.portfoliq.ai, and our public APIs. Out of scope: third-party services we rely on, denial-of-service testing, social engineering, physical attacks, and automated scanning that degrades service for other users.

What to expect

We will acknowledge your report, keep you informed as we investigate, and let you know when the issue is resolved. We ask that you act in good faith, avoid privacy violations and data destruction, and only interact with accounts you own or have explicit permission to test.

Questions about this policy? Contact security@portfoliq.ai.