Skip to content

Security: trnt-ai/.github

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you believe you have found a security vulnerability in a Trent product, service, or repository, please report it privately to security@trent.ai.

Please do not report security issues through public GitHub issues, discussions, or pull requests.

To help us triage quickly, include where possible:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce (proof of concept, affected URLs, code, or configuration)
  • Affected repository, component, or version
  • Any suggested remediation

What to Expect

  • We will acknowledge your report within 3 business days.
  • We will keep you informed as we investigate and remediate.
  • With your permission, we are happy to credit you once the issue is resolved.

Responsible Disclosure

We support responsible disclosure. When researching, please:

  • Allow us reasonable time to investigate and fix the issue before any public disclosure.
  • Avoid accessing, modifying, or deleting data that isn't yours; use test accounts where possible.
  • Do not perform denial-of-service, spam, social engineering, or physical attacks.

We will not pursue legal action against researchers who act in good faith and follow this policy.

Bug Bounty

Trent does not operate a bug bounty program and does not offer monetary rewards for vulnerability reports. Valid reports are appreciated and can be publicly acknowledged.

There aren't any published security advisories