Vulnerability Disclosure Policy
Trinity Technology Services, LLC (TrinityCorp). Version 1.0. Effective 22 September 2026. Reviewed annually. Contact security@trinitycorp.ai.
TrinityCorp welcomes good-faith reports of security problems affecting the customer portal, trinitycorp.ai and its subdomains, or the Orchestrator API at orchestrator.trinitycorp.ai.
Authorized research
Test only with your own account and data, avoid privacy violations and service degradation, and stop immediately if you reach personal data. Denial of service, social engineering, spam, destructive testing and prompt injection against another customer's data are not authorized.
Research carried out in good faith and in line with the policy is authorized and covered by our safe-harbour commitment.
Report a vulnerability
Email security@trinitycorp.ai with the vulnerability, affected location, reproduction steps and any suggested fix. Reports may be anonymous and may be submitted in English or Spanish.
We acknowledge reports within three business days, provide an initial severity assessment within ten business days, and target fixes within seven days for critical issues, thirty days for high issues and ninety days for medium issues.