Legal
Responsible disclosure
How to report a security vulnerability in PubTrust, and what you can expect from us when you do.
How do I report a vulnerability?
Email security@pubtrust.cc. We will acknowledge within one business day and give you a substantive response, not a holding message, within five. We do not require an NDA to accept a report, we will not threaten you, and we will credit you publicly unless you ask us not to. If you find a way to make our tag break a page, that is a security report as far as we are concerned and we would like to hear about it with the same urgency as anything else.
What is in scope?
- The PubTrust tag served from
cdn.pubtrust.cc— including any way to make it break or slow down a page it is installed on. - Beacon ingest and configuration at
in.pubtrust.cc. - The dashboard, API and MCP server at
app.pubtrust.cc. - This website, pubtrust.cc.
How should I test?
- Use accounts and Sites you own. Do not access, modify or delete other customers' data.
- Do not degrade the service for others: no denial-of-service or volumetric testing.
- Give us a reasonable opportunity to fix an issue before you disclose it publicly.
We will not pursue or support legal action against research carried out in good faith within these guidelines.