Vulnerability Disclosure Policy
Last updated: June 8, 2026. Trooth, LLC.
Introduction
Trooth, LLC values the work of security researchers and the broader community in keeping our products and customers safe. This policy describes how to report a security vulnerability to us, what you can expect in return, and the conditions under which we will not pursue legal action against good-faith research.
Scope
This policy applies to security vulnerabilities affecting the trooth.co website, the Trooth Operating System backend at api.trooth.co, and any open-source library published by Trooth, LLC.
Findings on third-party services that Trooth uses as subprocessors should be reported to the relevant provider under their own disclosure program. We are happy to help coordinate where appropriate.
How to report
Send vulnerability reports to security@trooth.co. Please include a clear description of the issue, the affected asset or endpoint, the steps required to reproduce it, and any proof-of-concept material that helps us validate the finding. Reports written in English are processed fastest.
Our commitments
We acknowledge receipt of every report within three business days. We respond substantively within ten business days with our assessment and an expected remediation timeline. We will keep you informed as we work toward a fix, and we are happy to credit you publicly once the issue is resolved, if you wish.
Safe harbor
Trooth, LLC will not pursue legal action against security researchers who act in good faith and comply with this policy. Good faith means you make a reasonable effort to avoid privacy violations, degradation of service, and destruction or exfiltration of data; you do not access, modify, or retain customer data beyond the minimum necessary to demonstrate a vulnerability; and you give us a reasonable opportunity to remediate before any public disclosure.
Out of scope
Reports limited to the following are generally not eligible: volumetric denial-of-service attacks, social engineering of Trooth personnel or customers, physical attacks against Trooth facilities or staff, findings from automated scanners without a demonstrated impact, and missing security headers or best-practice recommendations without a concrete exploit.
Coordinated disclosure
We ask that you give us a reasonable opportunity to remediate a reported vulnerability before disclosing it publicly. We will work with you in good faith to agree on a disclosure timeline that protects our customers while recognizing your contribution.