Trust Centre · Responsible disclosure
Report a vulnerability
We welcome good-faith security research into our own systems. This policy is our authorisation for that research within the scope and conditions below, our safe-harbour commitment to you, and the response standard we hold ourselves to.
One channel
Email security@trustquant.co.uk. It reaches the founding engineers directly.
3 working days
Our target to acknowledge every report, with a human reply.
Safe harbour
No legal action over good-faith research conducted under this policy.
Section 01
Scope
This policy covers systems that TrustQuant Resilience Cloud Ltd. owns and operates. It deliberately excludes the customer environments we assess: our access to those is read-only and granted to us alone — we cannot and do not authorise security testing against anyone else's infrastructure.
In scope
- trustquant.co.uk and any subdomain operated by TrustQuant
- The TrustQuant platform application and its APIs (pilot environment)
- This website's forms, endpoints and hosted assets
Out of scope
- Customer cloud environments and customer data — we hold read-only access to these; nothing in this policy authorises you to test them
- Infrastructure belonging to our hosting, email or other third-party providers — report those to the vendor concerned
- Denial-of-service, volumetric or resource-exhaustion testing of any kind
- Social engineering or phishing of TrustQuant staff, and physical attacks on people or premises
- Raw automated-scanner output without a demonstrated, reproducible impact
Section 02
How to report
Email security@trustquant.co.uk. Reports go straight to the founding engineers — there is no ticketing layer between you and the people who will fix the issue. We do not yet publish a PGP key; if your report is especially sensitive, email us first without the details and we will arrange a secure channel.
Please include
- A description of the vulnerability and where you found it (URL, endpoint or component)
- Step-by-step instructions to reproduce it
- Your assessment of the impact — what an attacker could actually do
- Any proof-of-concept material, keeping captured data to the minimum needed
- How you would like to be credited, if at all
Section 03
What to expect from us
We are a small founding team, so these targets are what we hold ourselves to rather than what a large security operations centre would promise. If we are going to miss one, you will hear from us before the deadline, not after it.
Acknowledgement
Within 3 UK working days
A human reply confirming we have your report — not an auto-responder.
Triage decision
Within 5 UK working days of acknowledgement
Whether we confirm the issue, need more information, or believe it is out of scope — with reasons.
Progress updates
At least every 10 UK working days
While a confirmed issue remains open, you will not have to chase us for status.
Fix or mitigation
Within 30 days for critical issues
Confirmed critical vulnerabilities take priority over all feature work.
Coordinated disclosure
Agreed together, typically within 90 days
We will agree a public disclosure timeline with you rather than impose one.
Section 04
Safe harbour
TrustQuant will not pursue civil action against you, initiate a complaint to law enforcement about you, or support the prosecution of security research that is conducted in good faith and in line with this policy. We consider such research to be authorised activity for the purposes of the Computer Misuse Act 1990 with respect to the in-scope systems, and a permitted use under our terms of service. If a third party brings legal action against you for activity we consider consistent with this policy, we will make it known that your actions were conducted under our authorisation.
This commitment cannot override the independent rights of third parties, and it does not extend to testing customer environments or accessing customer data — those are never in scope. If you are unsure whether something is covered, ask us at security@trustquant.co.uk before you proceed.
Section 05
What we ask of you
The safe harbour above applies to research that respects these conditions:
- Test only the in-scope systems, and use your own accounts where the platform is involved
- Access, copy or retain only the minimum data needed to demonstrate the issue
- If you encounter personal data or another organisation's data, stop, do not retain it, and tell us in your report
- Do not degrade the service for other users
- Keep the vulnerability confidential until we have agreed a disclosure date together
- Do not make payment a condition of telling us what you found
We do not yet run a paid bug bounty programme — we are pre-launch, and we would rather tell you that plainly than imply rewards we cannot fund. We will thank you, credit you publicly on this page if you wish, and be straight with you about fix timelines.
Section 06
Machine-readable contact
This policy and our security contact are published in RFC 9116 format at /.well-known/security.txt, so researchers and automated tooling find the right inbox first time.
/.well-known/security.txt
Contact: mailto:security@trustquant.co.uk Expires: 2027-07-01T00:00:00.000Z Policy: https://trustquant.co.uk/trust/disclosure Canonical: https://trustquant.co.uk/.well-known/security.txt Preferred-Languages: en
Policy version 1.0 · July 2026 · TrustQuant Resilience Cloud Ltd.
Explore the Trust Centre