XOWE Security Notices
Last reviewed: 31 August 2026
There is no open security incident affecting XOWE, and none has been reported to date.
What this page is for
XOWE has no accounts, no sign-up and no password, which means we hold no email address for most of the people who use it. If a personal data breach affects data held for your installation, we cannot email you. This page is therefore where we publish security notices first, and it is the authoritative record: our Data Processing Addendum commits us to notifying affected Customers here without undue delay and in any event within 72 hours of becoming aware of a breach.
Alongside publishing here we send a push notification to devices where notifications are enabled, and an email where we do hold an address. If you want security notices by email, write to support@tivforge.com with the subject "Security notices" and we will add your address to that list and use it for nothing else.
What a notice will say
The nature of the breach; the categories and approximate number of data subjects and records affected, so far as we know at the time; the likely consequences; and what we have done and are doing about it. Where the full picture is not yet available, we publish what we have and update it as we learn more rather than waiting.
Reporting a vulnerability
If you have found a security problem in XOWE, the backend at api.tivforge.com or the
public document pages at xowe.tivforge.com, write to support@tivforge.com with
"Security" in the subject. Tell us what you found and how to reproduce it.
We will acknowledge within 5 business days, keep you informed while we fix it, and credit you if you want to be credited. Please give us a reasonable chance to fix the problem before you publish it. We will not pursue or support legal action over good-faith research that stays within these limits: test only against your own installation and your own data, do not access, modify or delete anyone else's data, do not degrade the service for others, do not use social engineering or physical attacks, and stop as soon as you have demonstrated the problem.
We run no paid bug bounty.
How the Service is secured
The technical and organisational measures are described in Annex B of the Data Processing Addendum, and what we hold and for how long is in the Privacy Policy.
Notice history
None. This page will list every notice we publish, newest first, and notices are never removed once published.
Contact
TivForge LLC 5144 Mabe Drive Holly Springs, NC 27540 United States support@tivforge.com