Report vulnerabilities safely

RESPONSIBLE DISCLOSURE.VEXTRACE TRUST.

Public operational summary. Contract-specific obligations, applicable law and signed agreements prevail.

Version 1.0 · 30 July 2026

Security researchers may report suspected vulnerabilities affecting VEXTRACE-owned public assets to security@vextrace.com.

Include

Asset, impact, reproduction steps, supporting evidence and a safe contact channel.

Do not

Access client data, degrade availability, persist in systems, perform social engineering, exfiltrate data or publicly disclose before coordination.

Response

Acknowledgement and remediation timelines depend on severity, reproducibility and operational impact.

This page is a general template and should be reviewed by qualified legal counsel before being treated as a final legal policy.