Vulnerability Disclosure Policy
Responsible disclosure
We welcome good-faith security research. If you find a vulnerability in a Trausto system, please report it privately first so we can investigate and fix it before public disclosure.
Trust & Compliance
Security is part of how we build and operate Trausto, not an afterthought. This page explains how to report vulnerabilities, what is in scope, and how we handle responsible disclosure.
Vulnerability Disclosure Policy
We welcome good-faith security research. If you find a vulnerability in a Trausto system, please report it privately first so we can investigate and fix it before public disclosure.
Reporting
Email vulnerability reports to [email protected]. Include the affected system, a clear description, reproduction steps, and proof-of-concept material where appropriate. For sensitive disclosures, contact us for a public key before sending details.
We do not currently run a paid bug bounty programme. With consent, we are happy to acknowledge researchers who report valid issues responsibly.
Acknowledgement
5 business days
We confirm receipt and let you know that the report is being reviewed.
Initial triage
14 days
We provide an initial severity assessment and coordinate remediation privately.
We aim to resolve critical vulnerabilities within 30 days and high-severity findings within 90 days. When public disclosure is appropriate, we coordinate timing with the reporter where possible.
RiskZone GmbH will not pursue civil or criminal action against researchers who act in good faith and follow this policy.
Intentional data theft, service disruption, social engineering, physical attacks, and DoS/DDoS testing are not covered by this safe harbor.
Security questions or disclosures?
Our security mailbox is reviewed by the responsible team.