← Back

Security Policy

Effective date: September 30, 2026

We welcome reports from security researchers. If you believe you've found a vulnerability in TraceWaves, please tell us privately so we can fix it before it's disclosed.

How to Report

  • Use the contact form and choose the topic Security.
  • Include what's affected, steps to reproduce, and the impact you observed. Don't include other people's data.
  • We'll reply to the email address you enter, usually within a few business days, and keep you updated until it's resolved.

Scope

  • The web app and API at tracewaves.app
  • This site, tracewaves.com
  • The TraceWaves native apps and the local scan agent

Out of scope: third-party services we use (such as sign-in providers and our network provider), denial-of-service or volume testing, social engineering, physical attacks, and reports from automated scanners without a demonstrated impact.

Safe Harbor

We won't pursue legal action against good-faith research that follows this policy. That means you:

  • Test only against your own account and data, and stop as soon as you reach anyone else's.
  • Avoid degrading the service, destroying data, or accessing more than needed to show the issue.
  • Give us reasonable time to fix the issue before sharing details publicly.

Rewards

We don't run a bug bounty program and can't offer payment, but we're glad to credit you once a fix ships if you'd like.

Machine-readable contact details are in security.txt.