Skip to content
Trausto

Trust & Compliance

Security at Trausto

Security is part of how we build and operate Trausto, not an afterthought. This page explains how to report vulnerabilities, what is in scope, and how we handle responsible disclosure.

Vulnerability Disclosure Policy

Responsible disclosure

We welcome good-faith security research. If you find a vulnerability in a Trausto system, please report it privately first so we can investigate and fix it before public disclosure.

In scope

  • app.trausto.com — the Trausto SaaS platform, including related subdomains, APIs, and authentication systems.
  • trausto.com — the public website and supporting infrastructure.

Out of scope

  • Social engineering against employees, contractors, or partners.
  • DoS, DDoS, brute-force, or resource-exhaustion testing.
  • Physical attacks or attempts to access facilities.
  • Third-party services outside our control.
  • Findings without a clear security impact.

Reporting

Send reports privately.

Email vulnerability reports to [email protected]. Include the affected system, a clear description, reproduction steps, and proof-of-concept material where appropriate. For sensitive disclosures, contact us for a public key before sending details.

We do not currently run a paid bug bounty programme. With consent, we are happy to acknowledge researchers who report valid issues responsibly.

Response commitments

Acknowledgement

5 business days

We confirm receipt and let you know that the report is being reviewed.

Initial triage

14 days

We provide an initial severity assessment and coordinate remediation privately.

We aim to resolve critical vulnerabilities within 30 days and high-severity findings within 90 days. When public disclosure is appropriate, we coordinate timing with the reporter where possible.

Safe harbor

RiskZone GmbH will not pursue civil or criminal action against researchers who act in good faith and follow this policy.

  • Report issues promptly and privately.
  • Access only what is necessary to demonstrate the issue.
  • Do not modify, delete, or exfiltrate data.
  • Avoid public disclosure until we have had time to fix the issue.

Intentional data theft, service disruption, social engineering, physical attacks, and DoS/DDoS testing are not covered by this safe harbor.

Security questions or disclosures?

Our security mailbox is reviewed by the responsible team.

Contact security