Security policy
We take the security of A8 Core™ and the institutions that build on it seriously. This policy describes our practices and how to report a vulnerability.
Effective June 17, 2026
1. Our practices
A8 Core™ is built to the control expectations of regulated financial infrastructure: encryption in transit (TLS 1.3, TLS 1.2 minimum) and at rest (AES-256), HMAC-signed requests, HSM-backed key isolation, least-privilege access with SSO and MFA, continuous monitoring, and annual third-party penetration testing. See our trust center for certifications and to request our security package.
2. Reporting a vulnerability
If you believe you’ve found a security issue, report it through our bug bounty program or email security@a8core.com using our PGP key. Please include clear reproduction steps and a proof of concept, and give us a reasonable opportunity to remediate before public disclosure.
3. Safe harbor
We will not pursue or support legal action against researchers who act in good faith, comply with this policy, avoid privacy violations and service disruption, and do not access or modify data beyond what is necessary to demonstrate a vulnerability.
4. Scope
In scope: api.a8core.io, app.a8core.com, a8core.com/, and official SDKs. Out of scope: denial-of-service, social engineering, and third-party services not operated by A8 Core™. The full scope is listed on the bug bounty page.
5. Our commitment
We acknowledge reports within two business days, aim to triage within five, and will keep you updated through remediation. Valid reports are eligible for a reward and, with your permission, recognition.
Questions about this policy? Contact legal@a8core.com or write to Financial Infrastructure, Inc., PO Box 1410, Menlo Park, California 94026-1410.