← Back
Security Policy
Effective date: September 30, 2026
We welcome reports from security researchers. If you believe you've found a vulnerability in TraceWaves, please tell us privately so we can fix it before it's disclosed.
How to Report
- Use the contact form and choose the topic Security.
- Include what's affected, steps to reproduce, and the impact you observed. Don't include other people's data.
- We'll reply to the email address you enter, usually within a few business days, and keep you updated until it's resolved.
Scope
- The web app and API at
tracewaves.app - This site,
tracewaves.com - The TraceWaves native apps and the local scan agent
Out of scope: third-party services we use (such as sign-in providers and our network provider), denial-of-service or volume testing, social engineering, physical attacks, and reports from automated scanners without a demonstrated impact.
Safe Harbor
We won't pursue legal action against good-faith research that follows this policy. That means you:
- Test only against your own account and data, and stop as soon as you reach anyone else's.
- Avoid degrading the service, destroying data, or accessing more than needed to show the issue.
- Give us reasonable time to fix the issue before sharing details publicly.
Rewards
We don't run a bug bounty program and can't offer payment, but we're glad to credit you once a fix ships if you'd like.
Machine-readable contact details are in security.txt.