Skip to content

Security: AllTick-Official/alltick-realtime-forex-crypto-stock-tick-finance-websocket-api

Security

SECURITY.md

Security Policy

Reporting a Security Issue

If you discover a security vulnerability related to AllTick's software, API integration, documentation, or repository, please report it responsibly.

Please do not publicly disclose sensitive security details before the issue has been reviewed.

What to Include

When reporting a security issue, provide:

  • A clear description of the issue
  • The affected component or API
  • Steps to reproduce the issue
  • Potential security impact
  • Relevant logs or error messages, with sensitive information removed

Do not include:

  • API tokens
  • Passwords
  • Private keys
  • Personal credentials
  • Other sensitive or confidential information

API Credentials

Never commit AllTick API tokens or other private credentials to GitHub repositories.

If credentials are accidentally exposed, revoke or rotate them immediately.

Responsible Disclosure

We appreciate responsible security research and will review reported security issues as soon as reasonably possible.

Security issues should not be used to access, modify, or disrupt systems or data that you do not own or have explicit permission to test.

Scope

This policy applies to the AllTick GitHub repositories and developer resources maintained by the AllTick project.

For general API questions, documentation issues, feature requests, or integration problems, please use GitHub Issues or Discussions instead.

There aren't any published security advisories