Responsible Disclosure Policy

Last updated: 2026-01-15

Our Commitment

Tripzox takes security seriously. We appreciate the security research community and welcome responsible disclosure of potential vulnerabilities.

Reporting a Vulnerability

If you discover a security vulnerability, please report it to security@tripzox.com with a detailed description, steps to reproduce, and potential impact. Do not publicly disclose until we have had reasonable time to address the issue.

What to Expect

We will acknowledge receipt within two business days and provide a timeline for investigation and remediation. We will not pursue legal action against researchers who follow this policy in good faith.

Out of Scope

Social engineering, physical security, denial-of-service attacks, and issues in third-party services not controlled by Tripzox are out of scope.