Vulnerability Disclosure Policy
Last updated: July 2, 2026
Portfoliq welcomes reports from security researchers and the public about potential vulnerabilities in our services. This policy explains how to report an issue and what to expect in return.
How to report
Email security@portfoliq.ai with a description of the issue, the steps to reproduce it, and any supporting material (proof-of-concept, screenshots, logs). Please give us a reasonable opportunity to investigate and remediate before any public disclosure.
Scope
In scope: portfoliq.ai and app.portfoliq.ai, and our public APIs. Out of scope: third-party services we rely on, denial-of-service testing, social engineering, physical attacks, and automated scanning that degrades service for other users.
What to expect
We will acknowledge your report, keep you informed as we investigate, and let you know when the issue is resolved. We ask that you act in good faith, avoid privacy violations and data destruction, and only interact with accounts you own or have explicit permission to test.
Questions about this policy? Contact security@portfoliq.ai.