If you believe you have found a security vulnerability in a Trent product, service, or repository, please report it privately to security@trent.ai.
Please do not report security issues through public GitHub issues, discussions, or pull requests.
To help us triage quickly, include where possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof of concept, affected URLs, code, or configuration)
- Affected repository, component, or version
- Any suggested remediation
- We will acknowledge your report within 3 business days.
- We will keep you informed as we investigate and remediate.
- With your permission, we are happy to credit you once the issue is resolved.
We support responsible disclosure. When researching, please:
- Allow us reasonable time to investigate and fix the issue before any public disclosure.
- Avoid accessing, modifying, or deleting data that isn't yours; use test accounts where possible.
- Do not perform denial-of-service, spam, social engineering, or physical attacks.
We will not pursue legal action against researchers who act in good faith and follow this policy.
Trent does not operate a bug bounty program and does not offer monetary rewards for vulnerability reports. Valid reports are appreciated and can be publicly acknowledged.