Legal
Responsible Disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in trustnetsecure.com or another TrustNet Secure system, please tell us so we can fix it.
How to report
Email support@trustnetsecure.com with the subject "Security vulnerability report". Include the affected URL or system, steps to reproduce, the impact you observed and how to contact you. Our contact details are also published in security.txt.
Please
- Test only against your own accounts and data, and stop as soon as you have confirmed the issue.
- Do not access, change or delete other people's data.
- Do not run denial-of-service, spam or social-engineering attacks, or physical attacks.
- Do not use automated scanners that generate heavy traffic.
- Give us reasonable time to fix the issue before sharing it publicly.
What you can expect
- An acknowledgement of your report and updates as we investigate.
- We will not pursue legal action against researchers who act in good faith and within this policy.
- With your permission, we will credit you once the issue is fixed.
Out of scope
- Third-party services we link to (for example The Hacker News, WhatsApp, Google Maps).
- Reports that only list missing best-practice headers without a demonstrated impact, or results of automated scans alone.
- Clickjacking on pages with no sensitive actions, self-XSS and issues that require a compromised device.