TRUVO360 welcomes responsible disclosure from security researchers. If you believe you've found a vulnerability, please email [email protected]. We respond within 72 hours and work with you on a coordinated fix. We do not currently offer monetary bounties, but we credit confirmed reporters in our acknowledgments page with permission.

Scope

• In scope: truvo360.com and its API surface under /api/*.

• Out of scope: third-party infrastructure and payment providers — report those directly to the respective vendor.

• Not accepted: automated scanner output without manual validation, social engineering, physical attacks, denial-of-service.

Safe Harbor

Research conducted in good faith under this policy is considered authorized. We will not pursue legal action against researchers who act in good faith, avoid privacy violations, do not degrade our service, and give us a reasonable window to fix issues before public disclosure.