Skip to main content

Security and responsible disclosure

Report security concerns safely

Use the dedicated QueueRove security subject, protect other people's data, and keep secrets and live customer records out of the report.

  • Version 2026-08-02.1
  • Effective date: August 2, 2026
  • SHA-256 cc41d9a22282ea14caa6c7a6d986164732300687498e18c4570447cd6d6a74bc

Version and integrity

This is the current published version of this document. Material changes receive a new immutable version, a new content hash, and an archive entry.

The content hash is derived from the versioned structured source rendered on this page. Material changes receive a new version, an archive entry, and, where required, reacceptance.

Open the immutable archive route for this version → · View all archived documents

1. Report a suspected issue

Email support@queuerove.com with the subject QueueRove security report. Include a concise summary, affected QueueRove surface/version, approximate time, non-sensitive reproduction steps, and impact. The same contact is published at /.well-known/security.txt.

  • Do not include passwords, Client Secrets, access tokens, MFA or recovery codes, private keys, card data, HaloPSA customer records, or unredacted screenshots.
  • Do not access data or organizations you do not own or have explicit authorization to test.
  • Do not disrupt availability, degrade service, send malware, perform social engineering, or make a vulnerability public before coordinated review.
  • If a credential may be exposed, revoke or rotate it with the responsible provider or HaloPSA administrator first.

2. Response target

Initial response target for account takeover or critical security: 4 business hours. Business hours are Monday through Friday, 8:00 a.m. to 5:00 p.m. Central Time, excluding U.S. federal holidays. This is not a resolution or remediation SLA, and no bounty is offered or implied.

3. Web control-plane boundary

QueueRove treats server-side sessions, database state, explicit organization context, composable grants, recent MFA, immutable audit evidence, signed webhooks, and reconciliation as authority. Browser state, URL parameters, email possession, provider redirects, and provider state alone are not authority.

4. Mobile and HaloPSA boundary

The native clients connect directly to the customer-configured HaloPSA environment and keep working state on the device. HaloPSA credentials and customer records are not part of the website DPA scope. When reporting a mobile issue, include the app version and platform so it can be checked against the exact release.

5. Customer security actions

  • Protect devices, authentication factors, recovery material, and sessions; revoke lost devices and suspicious sessions promptly.
  • Use least-privilege HaloPSA and QueueRove grants and remove access when duties change.
  • Confirm queued work in HaloPSA before repeating actions or clearing device-local state.
  • Use the dedicated privacy, deletion, and support workflows; generic email is not authority for sensitive changes.

6. Incident communications

QueueRove may publish incident notices through the website or control panel as appropriate. No dedicated status service is claimed. Notification timing and content depend on verified facts, safety, applicable law, provider coordination, and any signed agreement.

Questions may be sent to support@queuerove.com with the subject “QueueRove security report”.