Service status ·A8 Core™ · The Operating System for Financial Accounts ·The account operating system · API-first
Trust Center · Security

Vulnerability disclosure.

If you believe you have found a security vulnerability in A8 Core™ or a8core.com, we want to hear from you — directly, safely, and first.

How to report

Email security@a8core.com with the affected URL or endpoint, steps to reproduce, and the impact you believe is possible. Encrypted mail is welcome; include your key or ask for ours.

We will acknowledge your report promptly, keep you informed as we investigate, and credit you (with your permission) when a fix ships. We ask that you give us a reasonable window to remediate before public disclosure, avoid accessing data that is not yours, and avoid testing that degrades service.

Safe harbor

Good-faith research conducted under this policy is authorized.

We will not pursue or support legal action against researchers who act in good faith, stay within the scope above, and report their findings to us directly. This page, referenced from /.well-known/security.txt, is the canonical statement of that policy.

Scroll to Top