Trust
Vulnerability disclosure policy
We welcome good-faith security research that helps keep Acretix and its customers safe.
Scope
Link to this sectionThis policy covers Acretix Deals, the Acretix Verify API and console, and acretix.io.
Out of scope
Link to this section- Denial of service.
- Social engineering.
- Physical attacks.
- Spam.
- Third-party services, such as Stripe, Supabase, and Vercel.
Rules for good-faith research
Link to this section- Test only accounts you own.
- Do not access, change, or keep other people's data beyond what proves the issue.
- Stop and report if you reach customer data.
- Do not run high-volume automated scanning.
- Allow 90 days before any public disclosure.
Safe harbor
Link to this sectionResearch within these rules is authorized. Acretix will not take legal action against it or ask others to, and will say so if a third party does.
What Acretix commits to
Link to this sectionWe will send a first reply within one business day and provide updates until the fix.
Thanks
Link to this sectionWith your permission, we will offer public credit for your report. We offer no cash rewards.
How to report
Link to this sectionEmail support@acretix.io with a clear description, steps to reproduce, and any supporting evidence.
Our contact details are also published at /.well-known/security.txt. Please write in English.
Last updated September 2026.