Skip to main content

Archived Security and responsible disclosure

Report security concerns safely

Use the dedicated QueueRove security subject, protect other people's data, and keep secrets and live customer records out of the report.

  • Version 2026-08-02.1
  • Effective date: August 2, 2026
  • SHA-256 d3462069a1bca83aaca02c01b27d556b1f8a096630bfb64aa3ef3e5346edc3f8

Archived version

This is the current published version of this document. Material changes receive a new immutable version, a new content hash, and an archive entry.

The content hash is derived from the versioned structured source rendered on this page. Material changes receive a new version, an archive entry, and, where required, reacceptance.

View the current stable route → · View all archived documents

1. Report a suspected issue

Email support@itecsonline.com with the subject QueueRove security report. Include a concise summary, affected QueueRove surface/version, approximate time, non-sensitive reproduction steps, and impact. The same contact is published at /.well-known/security.txt.

  • Do not include passwords, Client Secrets, access tokens, MFA or recovery codes, private keys, card data, HaloPSA customer records, or unredacted screenshots.
  • Do not access data or organizations you do not own or have explicit authorization to test.
  • Do not disrupt availability, degrade service, send malware, perform social engineering, or make a vulnerability public before coordinated review.
  • If a credential may be exposed, revoke or rotate it with the responsible provider or HaloPSA administrator first.

2. Response target

Initial response target for account takeover or critical security: 4 business hours. Business hours are Monday through Friday, 8:00 a.m. to 5:00 p.m. Central Time, excluding U.S. federal holidays. This is not a resolution or remediation SLA, and no bounty is offered or implied.

3. Web control-plane boundary

QueueRove treats server-side sessions, database state, explicit organization context, composable grants, recent MFA, immutable audit evidence, signed webhooks, and reconciliation as authority. Browser state, URL parameters, email possession, provider redirects, and provider state alone are not authority.

4. Mobile and HaloPSA boundary

The native clients connect directly to the customer-configured HaloPSA environment and keep working state on the device. HaloPSA credentials and customer records are not part of the website DPA scope. When reporting a mobile issue, include the app version and platform so it can be checked against the exact release.

5. Customer security actions

  • Protect devices, authentication factors, recovery material, and sessions; revoke lost devices and suspicious sessions promptly.
  • Use least-privilege HaloPSA and QueueRove grants and remove access when duties change.
  • Confirm queued work in HaloPSA before repeating actions or clearing device-local state.
  • Use the dedicated privacy, deletion, and support workflows; generic email is not authority for sensitive changes.

6. Incident communications

QueueRove may publish incident notices through the website or control panel as appropriate. No dedicated status service is claimed. Notification timing and content depend on verified facts, safety, applicable law, provider coordination, and any signed agreement.

Questions may be sent to support@itecsonline.com with the subject “QueueRove security report”.