Report vulnerabilities safely
RESPONSIBLE DISCLOSURE.VEXTRACE TRUST.
Public operational summary. Contract-specific obligations, applicable law and signed agreements prevail.
Version 1.0 · 30 July 2026
Security researchers may report suspected vulnerabilities affecting VEXTRACE-owned public assets to security@vextrace.com.
Include
Asset, impact, reproduction steps, supporting evidence and a safe contact channel.
Do not
Access client data, degrade availability, persist in systems, perform social engineering, exfiltrate data or publicly disclose before coordination.
Response
Acknowledgement and remediation timelines depend on severity, reproducibility and operational impact.
This page is a general template and should be reviewed by qualified legal counsel before being treated as a final legal policy.