AbateIQ

security

Trust & Security

Security & Responsible Disclosure

AbateIQ takes security seriously. We welcome responsible disclosure of security vulnerabilities and appreciate researchers who help us protect customer data, maintain service reliability, and improve the security of our platform.

Report a Vulnerability

If you believe you have found a security issue in AbateIQ, please report it to us at:

Email: [email protected]

Please include:

  • A clear description of the issue
  • Steps to reproduce the behavior
  • Affected URLs, endpoints, or workflows
  • Screenshots, logs, or proof-of-concept details as needed
  • Your assessment of potential impact
We aim to acknowledge receipt of vulnerability reports within 48 hours.

Scope

In Scope

  • app.abateiq.com
  • AbateIQ application APIs and backend services
  • Authentication and account access controls
  • File uploads, storage, and data handling features
  • Security issues that could affect confidentiality, integrity, or availability

Out of Scope

  • Social engineering or phishing
  • Physical attacks against people, offices, or infrastructure
  • Denial of Service or load testing
  • Spam or email best-practice issues without security impact
  • Vulnerabilities in third-party services not owned or controlled by AbateIQ

Responsible Research Guidelines

To help us investigate efficiently and reduce risk to customers, please follow these guidelines:

  • Act in good faith and avoid privacy violations.
  • Do not access, alter, delete, or exfiltrate data that is not your own.
  • Do not attempt to disrupt service availability, degrade performance, or damage systems.
  • Use the minimum necessary testing to demonstrate the issue.
  • Do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate it.

Safe Harbor

We consider security research conducted in accordance with this policy to be authorized.

AbateIQ will not pursue legal action against individuals who act in good faith, follow this policy, avoid customer harm, and promptly report discovered vulnerabilities to us.

Response Process

Step 1
Acknowledge

We confirm receipt of your report, typically within 48 hours.

Step 2
Validate

We investigate the issue, verify scope, and assess severity and impact.

Step 3
Remediate

We fix or mitigate the issue based on risk, complexity, and customer impact.

Step 4
Close the Loop

We communicate resolution or next steps when appropriate.

Rewards & Recognition

AbateIQ does not currently operate a formal public bug bounty program. However, we may provide recognition for valid, impactful, and responsibly disclosed reports at our discretion.

Public acknowledgments, when applicable and approved by the reporter, are listed on our Security Acknowledgments page.

Security Commitment

AbateIQ is committed to protecting customer information, maintaining secure application workflows, and continuously improving our controls and operational practices as the platform grows.