How to report
Email founder@tropiro.com with:
- The affected URL, component, or repository.
- A concise description of the issue and likely impact.
- Reproduction steps or a non-destructive proof of concept.
- How we can contact you and whether you want public credit.
Please do not send secrets, personal data, or destructive payloads. If sensitive transfer is necessary, ask us to arrange an appropriate channel first.
Research expectations
- Test only Tropiro-owned assets that are publicly identified for testing.
- Do not access, modify, retain, or disclose another person’s data.
- Do not disrupt availability, degrade service, or conduct denial-of-service testing.
- Do not use social engineering, physical testing, credential stuffing, or third-party infrastructure.
- Stop when you have enough evidence to explain the issue safely.
What to expect
We aim to acknowledge a credible report within five business days, keep the reporter informed during investigation, and coordinate disclosure after a fix is available. These are targets rather than a bug-bounty promise. Tropiro does not currently operate a paid vulnerability reward program.