This Security Policy outlines FirstQuadrant Inc.’s (“FirstQuadrant”, “we”, “us”, or “our”) approach to security and how we handle security-related reports and vulnerabilities.
We take security seriously and are committed to protecting our users’ data and maintaining the security of our services. We implement industry-standard security measures and regularly review and update our security practices.
We do not currently operate a bug bounty program, but we welcome responsible disclosure of security vulnerabilities and can evaluate on a case by case basis. If you discover a security vulnerability in our services, we encourage you to report it to us directly. We welcome reports of high-impact issues, including (but not limited to):
Insecure Direct Object References (IDOR)
Cross-Site Scripting (XSS)
Server-Side Request Forgery (SSRF)
Remote Code Execution (RCE)
SQL Injection or command injection
Broken access controls or authentication logic
Sensitive data exposure (e.g., secrets, tokens, credentials)
Misconfigured OAuth or JWT implementations
Business logic flaws that could lead to abuse or fraud
These issues must be demonstrated with clear, reproducible steps showing real impact.
We maintain a list of security researchers who have responsibly disclosed vulnerabilities to us. If you would like to be credited for your report, please let us know when submitting your findings.
We may update this security policy from time to time. We encourage you to review this policy periodically to stay informed about our security practices and reporting procedures.