Secure the Future.
Get Rewarded.
TrustProof is committed to the highest standards of security. We invite ethical hackers and security researchers to help us identify and fix vulnerabilities.
Reward Tiers
Payouts are determined by the severity and impact of the vulnerability. Bonuses are awarded for clear reproduction steps and PoC code.
Remote code execution, full system compromise, or direct access to sensitive customer data without authentication.
Significant impact on confidentiality, integrity, or availability. Requires user interaction or specific conditions.
Moderate impact. May expose limited data or disrupt service for a specific user, but not the entire system.
Minor impact. Best practice violations or issues that require highly unlikely user interaction to exploit.
In Scope
- api.trustproof.io (All v1 endpoints)
- dashboard.trustproof.io (Web Application)
- Official SDKs (Node, Python, Go, Java, Rust)
- Cryptographic Sealing & Merkle Tree logic
- Webhook signature verification mechanisms
Out of Scope
- Denial of Service (DDoS) attacks
- Social engineering or phishing of employees
- Physical security breaches
- Vulnerabilities in third-party dependencies (unless directly exploitable)
- Self-XSS or issues requiring browser extensions
Top Security Researchers
We publicly acknowledge the researchers who help keep our platform secure.
Safe Harbor Guarantee
If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized and will not pursue legal action against you. We will work with you to understand and resolve the issue quickly.
Read Full Legal PolicyFound a vulnerability?
Do not open a public GitHub issue. Please submit your findings through our secure portal.
Submit Report on HackerOne