Ir al contenido

Security & responsible disclosure

Esta página aún no está disponible en tu idioma.

Report vulnerabilities to security@trustysweep.com with reproduction steps and the affected surface. We acknowledge within two business days and target remediation of confirmed high-severity issues within 14 days. Use test mode (sk_test_) for research; never access data that is not yours. We do not pursue good-faith researchers who follow this policy.

Platform controls: tenant-scoped storage keys, encrypted credentials with key versioning, signed receipts, HMAC-signed webhooks with replay windows, OAuth 2.1 with PKCE and audience binding, immediate revocation, immutable usage and authorization ledgers, deterministic authorization outside any model.