Ximple Vulnerability Disclosure Policy

Last Updated: December 2025

Overview

Ximple welcomes feedback from security researchers to help keep our users and systems safe. We appreciate your efforts to responsibly disclose your findings and work with us privately to address security issues.

Scope

In Scope:

  • ximple.co and its subdomains
  • Ximple mobile applications (iOS and Android)
  • Ximple APIs used by our applications

Out of Scope:

  • Third-party services we use
  • Social engineering attacks
  • Physical security testing
  • Denial of Service (DoS) attacks

Guidelines

When testing, please:

  • Only test against accounts you own or have explicit permission to access
  • Respect user privacy – do not access, modify, or delete user data
  • Report vulnerabilities as soon as possible
  • Work with us privately and confidentially throughout the process
  • Avoid degrading our services or infrastructure

Please DO NOT:

  • Access or attempt to access data belonging to other users
  • Perform attacks that could harm service availability
  • Execute social engineering against our employees or customers
  • Conduct physical security tests of our facilities
  • Publicly disclose vulnerabilities at any time

How to Report

Email: [email protected]

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Your suggested remediation (if applicable)

Confidentiality: All vulnerability reports will be handled confidentially. We do not publicly disclose security vulnerabilities or researcher identities.

What to Expect

  • Initial Response: Within 3 business days
  • Status Updates: We’ll keep you informed of our progress
  • Resolution Timeline: Varies by severity, but we aim for 90 days maximum
  • Confidentiality: All communications will remain private

Safe Harbor

Ximple commits to:

  • Not pursue legal action against researchers who follow this policy
  • Work with researchers to understand and validate reports
  • Treat all reports confidentially

Rewards

We currently operate a Vulnerability Disclosure Program (not a bug bounty). While we don’t offer monetary rewards at this time, we appreciate your contribution to improving fintech security.

This policy is not a contract and may be modified at any time. Following this policy does not grant permission to violate any applicable laws.

Contact

For questions about this policy: [email protected]

Thank you for helping keep Ximple and our users safe!