All developer channels are staffed by engineers who work on the platform daily.
Channels
| Channel | Use for | Response |
|---|---|---|
| developers@qashx.io | API bugs, integration help, sandbox issues. | Business hours, < 1 business day. |
| security@qashx.io | Vulnerability disclosure. PGP available. | Acknowledged < 24 h. |
| incidents@qashx.io | Live production impact — payments failing. | 24/7 pager, < 30 min. |
| compliance@qashx.io | AML/KYC blocks, sanctions review, licensing. | Business hours, < 2 business days. |
| Status page | Live uptime and incidents. | Coming soon at /status.html. |
SLAs
| Plan | Response | Uptime target |
|---|---|---|
| Developer (free) | Best-effort, business hours. | 99.5% |
| Growth | < 4 business hours. | 99.9% |
| Enterprise | 24/7, < 30 min for P1. | 99.95% with financial credits. |
Writing a productive ticket
Include every item — it lets us skip the back-and-forth:
- The
request_idfrom the response (orX-Request-Idheader). - The environment (
testorlive) and the last 4 chars of the API key. - Full request URL, method, and redacted body.
- Full response status, headers, and body.
- The exact time (with timezone) the failure occurred.
- The behavior you expected vs what you observed.
Never send raw API keys or webhook secrets. If you must reference one, share only the last 4 characters.
Vulnerability disclosure
We follow coordinated disclosure. Report to security@qashx.io — do not open public issues.
- Acknowledgement within 24 hours.
- Fix ETA within 5 business days for High/Critical.
- Public credit on request after remediation.
- Bug bounty available for Enterprise-tier reporters.