Ximple Vulnerability Disclosure Policy
Last Updated: December 2025
Overview
Ximple welcomes feedback from security researchers to help keep our users and systems safe. We appreciate your efforts to responsibly disclose your findings and work with us privately to address security issues.
Scope
In Scope:
- ximple.co and its subdomains
- Ximple mobile applications (iOS and Android)
- Ximple APIs used by our applications
Out of Scope:
- Third-party services we use
- Social engineering attacks
- Physical security testing
- Denial of Service (DoS) attacks
Guidelines
When testing, please:
- Only test against accounts you own or have explicit permission to access
- Respect user privacy – do not access, modify, or delete user data
- Report vulnerabilities as soon as possible
- Work with us privately and confidentially throughout the process
- Avoid degrading our services or infrastructure
Please DO NOT:
- Access or attempt to access data belonging to other users
- Perform attacks that could harm service availability
- Execute social engineering against our employees or customers
- Conduct physical security tests of our facilities
- Publicly disclose vulnerabilities at any time
How to Report
Email: [email protected]
Please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Your suggested remediation (if applicable)
Confidentiality: All vulnerability reports will be handled confidentially. We do not publicly disclose security vulnerabilities or researcher identities.
What to Expect
- Initial Response: Within 3 business days
- Status Updates: We’ll keep you informed of our progress
- Resolution Timeline: Varies by severity, but we aim for 90 days maximum
- Confidentiality: All communications will remain private
Safe Harbor
Ximple commits to:
- Not pursue legal action against researchers who follow this policy
- Work with researchers to understand and validate reports
- Treat all reports confidentially
Rewards
We currently operate a Vulnerability Disclosure Program (not a bug bounty). While we don’t offer monetary rewards at this time, we appreciate your contribution to improving fintech security.
Legal
This policy is not a contract and may be modified at any time. Following this policy does not grant permission to violate any applicable laws.
Contact
For questions about this policy: [email protected]
Thank you for helping keep Ximple and our users safe!