Vulnerability disclosure
How to report a security issue, what we commit to in return, and the safe harbour that applies to good-faith research.
Last updated 23 July 2026 · Trust Center
1. How to report
Email security@a8core.com. Include enough detail to reproduce: affected endpoint or surface, steps, and what you observed. If the issue exposes data, describe it rather than sending it — do not attach records belonging to anyone else.
Please give us a reasonable opportunity to remediate before publishing. We will not ask you to stay quiet indefinitely and we will not use legal threats as a remediation strategy.
2. Safe harbour
If you make a good-faith effort to comply with this policy, we will treat your research as authorised, will not pursue or support a claim against you for it, and will say so if a third party raises one. Good faith means: you stop at the first proof, you access only data that is yours or clearly synthetic, you do not degrade service, you do not exfiltrate, and you tell us promptly.
If you are unsure whether something is in scope, ask first. We would rather answer a question than argue about an outcome.
3. In scope
- a8core.com and its subdomains that we operate
- The A8 Core™ API surface, including authentication and authorization behaviour
- Any case where a caller can reach a record it should not reach, in any tenant — this is the class we care about most
- Privilege escalation, delegation bypass, or defeating an approval gate
4. Out of scope
- Denial of service, volumetric or load testing, and anything that degrades service for others
- Social engineering of our people, customers or vendors, and physical access attempts
- Findings from automated scanners with no demonstrated impact
- Missing hardening headers or best-practice suggestions with no exploitable consequence — welcome as feedback, not treated as vulnerabilities
- Third-party services we do not operate. Report those to their owner; tell us too if our data is involved.
5. What we commit to
- Acknowledgement within two business days.
- An initial assessment, with a severity view and an indicative remediation window, within ten business days.
- Progress updates until it is closed, and confirmation when it is.
- Credit if you want it and anonymity if you prefer it.
We do not currently run a paid bounty programme, and we would rather say so than imply one.
6. Customer deployments
If a finding affects a specific customer’s configuration rather than the platform, we will notify that customer and coordinate. We will not disclose a customer’s identity or configuration to a reporter, and we will not delay telling the customer in order to manage the disclosure.
Financial Infrastructure, Inc. is a technology provider and is not a bank, trust company, broker-dealer or investment adviser. Nothing on this page is legal, regulatory, tax or investment advice. Institutional Trust Company is a proposed trust entity seeking a South Dakota non-depository trust charter; it is not yet chartered and is not accepting accounts.
Questions about this document? Contact security@a8core.com or write to Financial Infrastructure, Inc., PO Box 1410, Menlo Park, California 94026-1410.