Skip to content

Trust Centre · Responsible disclosure

Report a vulnerability

We welcome good-faith security research into our own systems. This policy is our authorisation for that research within the scope and conditions below, our safe-harbour commitment to you, and the response standard we hold ourselves to.

One channel

Email security@trustquant.co.uk. It reaches the founding engineers directly.

3 working days

Our target to acknowledge every report, with a human reply.

Safe harbour

No legal action over good-faith research conducted under this policy.

Section 01

Scope

This policy covers systems that TrustQuant Resilience Cloud Ltd. owns and operates. It deliberately excludes the customer environments we assess: our access to those is read-only and granted to us alone — we cannot and do not authorise security testing against anyone else's infrastructure.

In scope

  • trustquant.co.uk and any subdomain operated by TrustQuant
  • The TrustQuant platform application and its APIs (pilot environment)
  • This website's forms, endpoints and hosted assets

Out of scope

  • Customer cloud environments and customer data — we hold read-only access to these; nothing in this policy authorises you to test them
  • Infrastructure belonging to our hosting, email or other third-party providers — report those to the vendor concerned
  • Denial-of-service, volumetric or resource-exhaustion testing of any kind
  • Social engineering or phishing of TrustQuant staff, and physical attacks on people or premises
  • Raw automated-scanner output without a demonstrated, reproducible impact

Section 02

How to report

Email security@trustquant.co.uk. Reports go straight to the founding engineers — there is no ticketing layer between you and the people who will fix the issue. We do not yet publish a PGP key; if your report is especially sensitive, email us first without the details and we will arrange a secure channel.

Please include

  • A description of the vulnerability and where you found it (URL, endpoint or component)
  • Step-by-step instructions to reproduce it
  • Your assessment of the impact — what an attacker could actually do
  • Any proof-of-concept material, keeping captured data to the minimum needed
  • How you would like to be credited, if at all

Section 03

What to expect from us

We are a small founding team, so these targets are what we hold ourselves to rather than what a large security operations centre would promise. If we are going to miss one, you will hear from us before the deadline, not after it.

Acknowledgement

Within 3 UK working days

A human reply confirming we have your report — not an auto-responder.

Triage decision

Within 5 UK working days of acknowledgement

Whether we confirm the issue, need more information, or believe it is out of scope — with reasons.

Progress updates

At least every 10 UK working days

While a confirmed issue remains open, you will not have to chase us for status.

Fix or mitigation

Within 30 days for critical issues

Confirmed critical vulnerabilities take priority over all feature work.

Coordinated disclosure

Agreed together, typically within 90 days

We will agree a public disclosure timeline with you rather than impose one.

Section 04

Safe harbour

TrustQuant will not pursue civil action against you, initiate a complaint to law enforcement about you, or support the prosecution of security research that is conducted in good faith and in line with this policy. We consider such research to be authorised activity for the purposes of the Computer Misuse Act 1990 with respect to the in-scope systems, and a permitted use under our terms of service. If a third party brings legal action against you for activity we consider consistent with this policy, we will make it known that your actions were conducted under our authorisation.

This commitment cannot override the independent rights of third parties, and it does not extend to testing customer environments or accessing customer data — those are never in scope. If you are unsure whether something is covered, ask us at security@trustquant.co.uk before you proceed.

Section 05

What we ask of you

The safe harbour above applies to research that respects these conditions:

  • Test only the in-scope systems, and use your own accounts where the platform is involved
  • Access, copy or retain only the minimum data needed to demonstrate the issue
  • If you encounter personal data or another organisation's data, stop, do not retain it, and tell us in your report
  • Do not degrade the service for other users
  • Keep the vulnerability confidential until we have agreed a disclosure date together
  • Do not make payment a condition of telling us what you found

We do not yet run a paid bug bounty programme — we are pre-launch, and we would rather tell you that plainly than imply rewards we cannot fund. We will thank you, credit you publicly on this page if you wish, and be straight with you about fix timelines.

Section 06

Machine-readable contact

This policy and our security contact are published in RFC 9116 format at /.well-known/security.txt, so researchers and automated tooling find the right inbox first time.

/.well-known/security.txt

Contact: mailto:security@trustquant.co.uk
Expires: 2027-07-01T00:00:00.000Z
Policy: https://trustquant.co.uk/trust/disclosure
Canonical: https://trustquant.co.uk/.well-known/security.txt
Preferred-Languages: en

Policy version 1.0 · July 2026 · TrustQuant Resilience Cloud Ltd.

Explore the Trust Centre