SECURITY

Reporting security vulnerabilities

If you think you have found a security issue in a Trivore product or service, please tell us. We will work with you in good faith to understand the issue, fix it, and credit you when we publish the advisory.

How to reach us

Send your report to security@trivore.com.

Please include the following information:

  • The product, version and component you tested (the container image tag, if you have it).
  • Clear steps to reproduce the issue.
  • The impact you observed, or the impact you believe is possible.
  • Whether you have shared the report with anyone else, and any disclosure deadline you plan to apply.
  • The name or handle you would like us to use when we credit you, or let us know if you prefer to stay anonymous.

We accept advertisements in Finnish and English.

What you can expect from us

If we ever miss one of these, that is a failure on our side. Please remind us at security@trivore.com.

What the policy covers
  • Production releases of our identity and IAM products – specifically, the container images we publish.
  • Our public websites on trivore.com and its subdomains.
What the policy does not cover
  • Customer environments that are not your own. If you find an issue on a customer’s deployment, please report it to us – do not test further.
  • Denial-of-service or load testing of any kind against our infrastructure or our customers’.
  • Social engineering of our staff, our partners, or our customers.
  • Physical attacks on any premises.

Testing the items above is outside our safe-harbour commitment. If you are not sure whether something is covered, ask us before you test.

Safe harbour

If you act in good faith, follow this policy and stay within the law, we will treat your work as authorised security research. We will not take legal action against you, and we will not support anyone else who tries to.

In return we ask you to:

  • Stop testing and tell us as soon as you find a vulnerability.
  • Only access data you own. Do not download, modify or share anyone else’s data.
  • Give us a reasonable window to fix the issue before you discuss it publicly. Our default is 90 days from your initial report. If a fix takes longer, we will talk to you about extending – we will not silently let the clock run out.
Credit

When we publish an advisory we will credit you by the name or handle you gave us, unless you have asked to stay anonymous. If you would like a written reference for your work, we are happy to provide one.

Bug bounty

We do not currently pay monetary rewards. We will credit you publicly and gladly write a reference.

CVE assignment

We are not a CVE Numbering Authority. When a vulnerability warrants a CVE we request one from MITRE or the relevant national CNA and include it in the advisory.

Questions about this policy?

Email security@trivore.com.

We will update this policy at least annually.

Ask for a demonstration

Please fill in the form below and we will contact you to arrange a demonstration.

Ask for a demonstration

Please fill in the form below and we will contact you to arrange a demonstration.

New: See how much you can save with modern IAM