Security fixes target the latest published release.
Use GitHub private vulnerability reporting. You may also email support@xquik.com.
Do not open a public issue. Do not include secrets in screenshots, logs, or examples.
We aim to acknowledge reports within 3 business days. We coordinate disclosure after confirming the issue.
Security-sensitive areas include:
- API key and token handling
- Request construction and redirects
- Terminal output and local files
- Dependencies and generated code
- Release binaries, checksums, and provenance
Act in good faith and avoid privacy violations. Do not disrupt services or access unrelated data. We will not pursue good-faith research following this policy.
Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp.