Vulnerability Disclosure Policy
Last updated: August 2026 · Coordinated disclosure
1. Purpose
Trustline welcomes good-faith reports of security weaknesses in systems we own and operate. This policy describes how to report, what is in scope, and how we handle disclosure. It follows the intent of ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling).
2. How to report
Email contact@trustline.vn with the subject line [VDP]. Encrypt the message with our PGP public key when the report includes exploit details, tokens, or personal data.
Include, where possible:
- Affected URL, host, or product and the date/time of testing.
- A clear description of the issue and its security impact.
- Step-by-step reproduction. Proof-of-concept is welcome; keep it minimal.
- Your contact details and, if you want, a name for acknowledgement.
3. Scope
In scope: trustline.vn, www.trustline.vn, and official Trustline email domains. Client systems are never in scope of this policy — report those to the asset owner.
Out of scope:
- Denial of service, volumetric flooding, or resource exhaustion.
- Social engineering of Trustline staff, customers, or partners.
- Physical attacks, spam, and automated scanner output with no validated finding.
- Issues in third-party services we do not control.
4. Safe harbor
If you follow this policy, act in good faith, avoid privacy violations and service disruption, and do not access data beyond what is needed to demonstrate the issue, Trustline will not pursue legal action relating to that research. This is not permission to attack customer environments or to extort a payout.
5. Our handling
- We aim to acknowledge a valid report within 5 business days.
- Please allow 90 days for remediation before public disclosure, unless we agree a different window or an active exploit requires faster coordination.
- We do not currently operate a paid bug bounty. We will credit researchers who want to be named, once the issue is resolved.
6. Related
Machine-readable contact is published at /.well-known/security.txt. Personal data in reports is processed as described in our Privacy Policy.