# HAQQ Security Contact Information # https://haqq.ai # RFC 9116 Compliant # Last updated: 2026-07-10 # Security Contact Contact: mailto:security@haqq.ai Contact: https://haqq.ai/security # Encryption # PGP key available upon request to security@haqq.ai # Policy Policy: https://haqq.ai/security Policy: https://haqq.ai/terms-and-conditions # Acknowledgments # We appreciate security researchers who help keep HAQQ secure. Acknowledgments: https://haqq.ai/security#acknowledgments # Preferred Languages Preferred-Languages: en, ar, fr, es, it, de, pt # Canonical URL Canonical: https://haqq.ai/.well-known/security.txt # Expiration Expires: 2027-07-10T00:00:00.000Z # Hiring Hiring: https://haqq.ai/careers # ============================================================================ # VULNERABILITY DISCLOSURE POLICY # ============================================================================ # Scope # ----- # - haqq.ai and all subdomains # - HAQQ mobile applications (iOS, Android) # - HAQQ API endpoints # - Justinian AI Engine interfaces # Out of Scope # ------------ # - Social engineering attacks # - Physical security attacks # - Denial of service attacks # - Third-party services and applications # Reporting Guidelines # -------------------- # 1. Email security@haqq.ai with detailed vulnerability report # 2. Include steps to reproduce the issue # 3. Provide proof of concept if possible # 4. Allow reasonable time for remediation before disclosure # What We Promise # --------------- # - Acknowledgment within 48 hours # - Regular updates on remediation progress # - No legal action for good-faith research # - Credit in security acknowledgments (if desired) # What We Ask # ----------- # - Do not access or modify other users' data # - Do not disrupt our services # - Do not publicly disclose until we've addressed the issue # - Act in good faith # ============================================================================ # SECURITY & COMPLIANCE PROGRAM # ============================================================================ # HAQQ's security, privacy, and AI-governance program is designed to align # with the frameworks below. References to these frameworks describe alignment # with the relevant controls; they are not a representation that every product, # feature, or deployment is covered by a formal certification or audit. See # https://haqq.ai/security and the Terms of Service for authoritative scope. # SOC 2 Type II — compliant # - Program designed to align with the AICPA Trust Services Criteria # - Covers Security, Availability, Confidentiality # ISO/IEC 27001 — compliant # - Information Security Management System aligned to ISO/IEC 27001 # ISO/IEC 42001 — compliant # - AI Management System aligned to ISO/IEC 42001 (responsible AI governance) # GDPR — compliant # - EU data protection standards; privacy by design # ============================================================================ # SECURITY MEASURES # ============================================================================ # Encryption # - Data at rest: AES-256 # - Data in transit: TLS 1.3 # Access Controls # - Role-based access control (RBAC) # - Multi-factor authentication (MFA) # - Principle of least privilege # Monitoring # - Continuous security monitoring # - Automated vulnerability scanning # - Real-time alerting # Infrastructure # - Secure cloud hosting # - Ongoing security testing # ============================================================================ # INCIDENT RESPONSE # ============================================================================ # Security Incident Contact: security@haqq.ai # Emergency Contact: +961 (available upon request) # Response Times # - Critical: 4 hours # - High: 24 hours # - Medium: 72 hours # - Low: 7 days # ============================================================================ # ADDITIONAL CONTACTS # ============================================================================ # General: info@haqq.ai # Legal: legal@haqq.ai # Privacy: privacy@haqq.ai # Enterprise: enterprise@haqq.ai # Careers: careers@haqq.ai