RESPONSIBLE VULNERABILITY DISCLOSURE POLICY
At Trinex Security, security is at the core of everything we do. We welcome ethical security researchers, bug hunters, and security professionals to audit our systems and safely disclose vulnerabilities under our Safe Harbor guidelines.
OUR COMMITMENT TO RESEARCHERS
We value the global cybersecurity research community. If you believe you have discovered a vulnerability, security flaw, or exposed credential in any Trinex Security digital asset or product, we encourage you to report it to us immediately.
When you report a security issue in accordance with this policy, we commit to working collaboratively with you to investigate, validate, and remediate the issue promptly.
PROGRAM TESTING SCOPE
The following table outlines the assets included in our testing scope. Please restrict your security research strictly to these assets:
| Target Domain / Asset | Type | Scope Status |
|---|---|---|
https://trinexsecurity.com |
Primary Corporate Website | IN SCOPE |
*.trinexsecurity.com |
All Subdomains & API Endpoints | IN SCOPE |
| Third-Party SaaS Dependencies | Hosted Vendors (e.g. Email Providers) | OUT OF SCOPE |
RULES OF ENGAGEMENT & SAFE HARBOR
To qualify for Safe Harbor protection and avoid legal action, researchers must strictly adhere to the following rules:
- Do No Harm: Avoid privacy violations, destruction of data, degradation of user experience, or service disruption.
- No Automated Spamming or DoS: Do not execute Denial of Service (DoS/DDoS) attacks, automated volume fuzzing, or email spam.
- Respect User Privacy: If sensitive PII data is encountered, cease testing immediately and delete cached data.
- Confidentiality Mandate: Do not disclose or share vulnerability details publicly until Trinex Security has completed remediation.
Legal Safe Harbor Guarantee: If your security research complies with this policy, Trinex Security will consider your research authorized, will not initiate legal action, and will defend researchers against third-party claims.
HOW TO SUBMIT A VULNERABILITY REPORT
Submit your encrypted security report directly to our Incident Response & Security Engineering Team:
REPORT REQUIREMENTS
To assist us in validating your report quickly, please include:
- Clear step-by-step instructions or Proof of Concept (PoC) exploit scripts.
- Target URL, parameters, and HTTP request/response headers.
- Estimated impact and CVSS severity assessment.
RESPONSE TIMELINES & SLAS
- Initial Triage Acknowledgment: Within 24 hours of submission.
- Vulnerability Validation & Severity Assessment: Within 72 hours.
- Remediation Patch Deployment: 7 to 30 business days based on CVSS severity.