Product security and responsible disclosure

Security at Trivixx

Protecting our products, customers, and infrastructure through secure engineering, responsible access, and continuous improvement.

Security is considered throughout the way we design, develop, deploy, and maintain our software. We welcome responsible reports that help us identify and address legitimate security risks.

Security contact

security@trivixx.com

Acknowledgement target

Within two business days

Responsible disclosure

Good-faith research is welcome when this policy is followed.

Our approach

Our security commitment

Trivixx Technologies Private Limited is committed to protecting the confidentiality, integrity, and availability of the systems and information under our control.

Our security practices are designed to evolve alongside our products, infrastructure, customer requirements, and the broader threat landscape.

We avoid absolute claims about security. Instead, we focus on practical risk reduction, responsible engineering, appropriate access controls, timely maintenance, and clear incident response.

Responsible disclosure

Report a security vulnerability

If you believe you have discovered a security vulnerability affecting a Trivixx product, service, website, or system, please report it privately to:

security@trivixx.com

Please do not publicly disclose the issue before we have had a reasonable opportunity to investigate and address it.

What to include in your report

  • The affected product, service, website, or endpoint
  • A clear description of the vulnerability
  • Steps required to reproduce the issue
  • The potential security impact
  • Screenshots, logs, or proof of concept where appropriate
  • Your preferred contact details

What happens next

How we handle security reports

1

Report received

Your report is received by the Trivixx security contact.

2

Acknowledgement

We aim to acknowledge valid reports within two business days.

3

Assessment

We review reproducibility, impact, affected systems, and severity.

4

Investigation and remediation

The relevant team investigates and prepares appropriate corrective action.

5

Resolution

Where appropriate, we coordinate the fix and communicate the outcome.

These are target response stages. Actual timelines may vary depending on complexity, severity, affected systems, and the availability of sufficient technical information.

Testing boundaries

Scope

In scope

  • Trivixx websites and public web applications
  • Trivixx-managed APIs and authentication systems
  • TrivStay
  • TrivRx
  • TrivGo
  • TrivStone
  • Other products explicitly operated by Trivixx

Out of scope

  • Social engineering or phishing of employees, customers, or partners
  • Physical attacks against Trivixx offices, staff, or infrastructure
  • Denial-of-service, load, stress, or destructive testing
  • Automated testing that causes excessive traffic or service disruption
  • Spam, unsolicited messaging, or content-related complaints
  • Vulnerabilities in third-party services not controlled by Trivixx
  • Reports based only on outdated scanner output without demonstrated impact

Good-faith research

Safe harbour

Trivixx will not pursue legal action against individuals who conduct security research in good faith, comply with this policy, avoid privacy violations and service disruption, do not exploit vulnerabilities beyond what is reasonably necessary to demonstrate them, and provide us with reasonable time to investigate and remediate the reported issue.

This safe-harbour statement does not authorise unlawful activity, access to third-party data, destruction of data, extortion, denial-of-service testing, social engineering, or actions that create risk for our customers, employees, partners, or infrastructure.

Security practices

Our security principles

Secure development

Security considerations are incorporated into product design, engineering, testing, deployment, and maintenance.

Access control

Administrative and operational access is limited according to role, responsibility, and business need.

Data protection

We use appropriate technical and organisational measures to protect information handled by our systems.

Dependency monitoring

Software dependencies and infrastructure components are reviewed and updated as security issues are identified.

Infrastructure security

Our systems are configured with security, availability, monitoring, and maintainability in mind.

Continuous improvement

We review security practices as our products, operations, risks, and customer requirements evolve.

Products and updates

Product security

When a verified vulnerability affects a supported Trivixx product or service, we assess the potential impact and determine the appropriate corrective action.

Depending on the issue, remediation may include a software update, configuration change, infrastructure adjustment, operational mitigation, customer communication, or a combination of these measures.

Customers are responsible for applying updates, maintaining secure configurations, protecting credentials, and following applicable product guidance.

Contact the security team

For suspected vulnerabilities, security concerns, or questions about this policy, contact our security team.

security@trivixx.com