How to report
Email the security team. Please include:
- A description of the vulnerability and its impact
- The affected URL, system or service
- Steps to reproduce it, with screenshots or a proof of concept
- How we can reach you
Security
We take the security of our own systems as seriously as our clients'. If you believe you have found a vulnerability in a Trivick website or service, please report it to us privately.
Draft policy: the response times and the security mailbox are proposals, to be confirmed before launch.
Email the security team. Please include:
If you act in good faith and follow this policy, we will not take legal action against you for your research, and we will work with you to understand and fix the issue.
We do not publish a PGP key at the moment. Our security.txt file lists these details in a machine-readable form. security.txt