Vulnerability Disclosure Policy
Found a security problem? We want to hear about it.
We would rather learn about it from you than from an incident. This page says what is in scope, how to report, what we promise in return, and what we ask of you.
Effective September 24, 2026
How to report
Email security@tracendt.com. Encrypting is optional; if you want to, ask us for a key in a first message. Include what you found and where (URL, request, screen), steps to reproduce as precisely as you can, what an attacker could do with it, and your name or handle if you want to be credited — or a note that you do not.
Use an account you created yourself for testing; a free TRACE account takes a minute to set up. Do not test against another customer's account, and if you land in another tenant's data, stop, take only the minimum needed to show it, and report immediately.
The machine-readable version of this page is /.well-known/security.txt.
In scope
- www.tracendt.com and tracendt.com — the application and the public site
- status.tracendt.com
- The TRACE mobile app (the Android and iOS builds we distribute)
- The customer-facing token pages (/t/…), the client portal and the technician portal
- Our email: anything you can make TRACE send that it should not
Out of scope
- Our infrastructure providers' own systems — Supabase, Vercel, Stripe, Resend, Cloudflare, Google, Microsoft, Anthropic, Expo, GitHub. Report those to them; tell us too if TRACE's use of them is the problem.
- Denial of service, volumetric attacks, rate-limit exhaustion
- Social engineering of our staff or customers; physical attacks
- Reports from automated scanners with no demonstrated impact
- Missing best-practice headers or configuration with no exploit path, version disclosure, clickjacking on pages with nothing to click
- Anything that requires a rooted or jailbroken device, or a compromised browser
What we promise
- Acknowledgement within 3 business days.
- Triage and a severity within 10 business days, with a contact who will keep you informed.
- Fix targets from confirmation: critical (cross-tenant data access, authentication bypass, remote code execution) within 7 days; high within 30 days; medium within 90 days; low on our normal schedule.
- We will tell you when it is fixed, and we will not object to you publishing your findings 90 days after our acknowledgement or once the fix ships, whichever is sooner, as long as the publication does not expose customer data.
- Credit on this page if you want it. We do not run a paid bounty program today.
Safe harbor
If you make a good-faith effort to follow this policy, we consider your research authorized. We will not pursue or support legal action against you for it, and if a third party brings a claim against you for activity that complied with this policy, we will make it known that your actions were authorized. Good faith means:
- you did not access, modify or destroy data beyond what was needed to demonstrate the issue, and you did not retain it
- you did not degrade the service for others
- you did not use the finding to extort, and you gave us the time above before publishing
- you complied with the law
This safe harbor does not extend to activity against our providers, which their own policies govern.
Our own reporting
Where a report reveals a personal data breach affecting a customer, we notify that customer's primary user within 72 hours of confirming it, as our incident response plan says. Your report is confidential; we do not name reporters in those notices without consent.
Acknowledgements
None yet. Researchers who report a confirmed issue and ask to be credited are listed here.
How TRACE is protected day to day is on the Security page.