Skip to content

Security

Found a vulnerability? Tell us.

We take the security of our own systems as seriously as our clients'. If you believe you have found a vulnerability in a Trivick website or service, please report it to us privately.

Draft policy: the response times and the security mailbox are proposals, to be confirmed before launch.

How to report

Email the security team. Please include:

  • A description of the vulnerability and its impact
  • The affected URL, system or service
  • Steps to reproduce it, with screenshots or a proof of concept
  • How we can reach you
security@trivick.com

Scope

In scope

  • trivick.com and the subdomains Trivick operates
  • Other websites and services Trivick operates

Out of scope

  • Denial-of-service testing
  • Social engineering and physical attacks
  • Systems run by third parties, such as our hosting provider
  • Automated scanner reports without a demonstrated impact

Please

  • Access or change only what you need to demonstrate the issue, and no personal data
  • Do not disrupt our services or delete data
  • Give us reasonable time to fix the issue before telling anyone else

Safe harbour

If you act in good faith and follow this policy, we will not take legal action against you for your research, and we will work with you to understand and fix the issue.

We do not publish a PGP key at the moment. Our security.txt file lists these details in a machine-readable form. security.txt

Review build · draft copy
Base
Render