Skip to main content

Security & Vulnerability Disclosure

Last updated: 5 September 2026 · Altos IQ LLC

Altos IQ handles financial records belonging to businesses that are often being prepared for sale — some of the most sensitive information a company holds. If you have found a weakness in how we protect it, we would rather hear from you than not.

Reporting a vulnerability

Email [email protected]. Include enough detail to reproduce the issue — a URL, the request, and what you observed. If it is easier to show than describe, a short screen recording is welcome.

You do not need to know how serious it is. Report it and we will work that out.

What we commit to

  • We will acknowledge your report within three business days, from a person rather than an autoresponder.
  • We will tell you what we found when we have assessed it, including if we decide it is not a vulnerability and why.
  • We will not pursue legal action, or ask anyone else to, for good-faith research that follows the guidance below.
  • We will credit you by name if you want the credit, and say nothing if you do not.

We do not run a paid bug bounty. We would rather say so plainly than imply one.

In scope

  • altosiq.com and its subdomains
  • The Altos IQ web application, including its API
  • The embeddable lead-capture widget and the WordPress plugin

Out of scope

These are not things we will treat as vulnerabilities, and testing some of them puts other people at risk:

  • Denial of service, load testing, or anything that degrades the service for other users
  • Social engineering of our staff, customers, or vendors, including phishing
  • Physical attacks, or access to accounts you do not own
  • Findings from automated scanners with no demonstrated impact — a header that is missing is a finding only if you can show what it lets you do
  • Vulnerabilities in third-party services we use, which should go to that vendor

Please do not

  • Access, modify, or download data belonging to anyone else. If you can demonstrate access, stop there and tell us — you do not need to prove it twice.
  • Publish the issue before we have had a chance to fix it.
  • Use a finding to extract payment. That is not a disclosure.

If you accidentally reach data that is not yours, tell us what you saw and delete it. We will treat that as what it is — an accident during good-faith work — provided you tell us.

How we handle your report

We are a small team, so you will be dealing with a person and not a queue. We will keep you informed while we work on it, and we will tell you when it is fixed. If we decide not to fix something, we will explain why rather than going quiet.

Machine-readable

The same contact information is published at /.well-known/security.txt in the format described by RFC 9116.

Not a security question?

For privacy requests see our Privacy Policy. For anything else, use the contact details on our contact page.