Security and responsible disclosure
Report security concerns safely
Use the dedicated QueueRove security subject, protect other people's data, and keep secrets and live customer records out of the report.
- Version 2026-07-17-draft.1
- Effective date: Pending Texas counsel approval
- SHA-256
46c79362d583c4d7884b764c86cc0eecf2a4f6dd9436cc9be05e210176dde8e2
Review and release status
Technical draft pending Texas counsel review; production collection and charging also require tax/accounting signoff and explicit launch approval.
This repository-local document is not provider, deployment, counsel, tax, or production evidence. It makes no approval or launch claim.
The content hash is derived from the versioned structured source rendered on this page. Material changes require a new version, archive entry, and the approved reacceptance process.
Open the immutable archive route for this version → · View all archived documents
1. Report a suspected issue
Email support@itecsonline.com with the subject QueueRove security report. Include a concise summary, affected QueueRove surface/version, approximate time, non-sensitive reproduction steps, and impact. The same contact is published at /.well-known/security.txt.
- Do not include passwords, Client Secrets, access tokens, MFA or recovery codes, private keys, card data, HaloPSA customer records, or unredacted screenshots.
- Do not access data or organizations you do not own or have explicit authorization to test.
- Do not disrupt availability, degrade service, send malware, perform social engineering, or make a vulnerability public before coordinated review.
- If a credential may be exposed, revoke or rotate it with the responsible provider or HaloPSA administrator first.
2. Response target
Initial response target for account takeover or critical security: 4 business hours. Business hours are Monday through Friday, 8:00 a.m. to 5:00 p.m. Central Time, excluding U.S. federal holidays. This is not a resolution or remediation SLA, and no bounty is offered or implied.
3. Approved web control-plane boundary
The approved v1 design treats server-side sessions, database state, explicit organization context, composable grants, recent MFA, immutable audit evidence, signed webhooks, and reconciliation as authority. Browser state, URL parameters, email possession, provider redirects, and provider state alone are not authority.
Design is not deployment evidence
Repository code, tests, and this page do not prove provider configuration, staging isolation, penetration testing, restore performance, production monitoring, certification, or a breach-free history. Those claims require separate recorded evidence.
4. Mobile and HaloPSA boundary
The existing native clients are designed to connect directly to the customer-configured HaloPSA environment and keep working state on the device. HaloPSA credentials and customer records are not part of the website DPA scope. Exact mobile permissions, SDKs, credential storage, offline behavior, deletion controls, and disclosures must be verified from each signed release artifact; website work is not proof of mobile compliance.
5. Customer security actions
- Protect devices, authentication factors, recovery material, and sessions; revoke lost devices and suspicious sessions promptly.
- Use least-privilege HaloPSA and QueueRove grants and remove access when duties change.
- Confirm queued work in HaloPSA before repeating actions or clearing device-local state.
- Use the dedicated privacy, deletion, and support workflows; generic email is not authority for sensitive changes.
6. Incident communications
QueueRove may publish incident notices through the website or control panel as appropriate. No dedicated status service is claimed. Notification timing and content depend on verified facts, safety, applicable law, provider coordination, and any signed agreement.
Related resources
Questions may be sent to support@itecsonline.com with the subject “QueueRove security report”.