Vulnerability Disclosure

Secure the Future.
Get Rewarded.

TrustProof is committed to the highest standards of security. We invite ethical hackers and security researchers to help us identify and fix vulnerabilities.

Reward Tiers

Payouts are determined by the severity and impact of the vulnerability. Bonuses are awarded for clear reproduction steps and PoC code.

Critical
$15,000 - $50,000

Remote code execution, full system compromise, or direct access to sensitive customer data without authentication.

Common Examples
RCESQL InjectionAuth Bypass
High
$5,000 - $15,000

Significant impact on confidentiality, integrity, or availability. Requires user interaction or specific conditions.

Common Examples
XSSIDORPrivilege Escalation
Medium
$1,000 - $5,000

Moderate impact. May expose limited data or disrupt service for a specific user, but not the entire system.

Common Examples
CSRFOpen RedirectInfo Disclosure
Low
$100 - $1,000

Minor impact. Best practice violations or issues that require highly unlikely user interaction to exploit.

Common Examples
Missing HeadersRate LimitingMinor UI Bugs

In Scope

  • api.trustproof.io (All v1 endpoints)
  • dashboard.trustproof.io (Web Application)
  • Official SDKs (Node, Python, Go, Java, Rust)
  • Cryptographic Sealing & Merkle Tree logic
  • Webhook signature verification mechanisms

Out of Scope

  • Denial of Service (DDoS) attacks
  • Social engineering or phishing of employees
  • Physical security breaches
  • Vulnerabilities in third-party dependencies (unless directly exploitable)
  • Self-XSS or issues requiring browser extensions
Hall of Fame

Top Security Researchers

We publicly acknowledge the researchers who help keep our platform secure.

0xHunter
12 validated findings
$45,000
Max Reward
NullPointer
8 validated findings
$22,000
Max Reward
CipherBreaker
5 validated findings
$15,000
Max Reward
PacketSniffer
4 validated findings
$8,500
Max Reward
RootCause
3 validated findings
$12,000
Max Reward
ZeroDayZ
2 validated findings
$5,000
Max Reward

Safe Harbor Guarantee

If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized and will not pursue legal action against you. We will work with you to understand and resolve the issue quickly.

Read Full Legal Policy

Found a vulnerability?

Do not open a public GitHub issue. Please submit your findings through our secure portal.

Submit Report on HackerOne