170TARV / PLATFORM TRUST

Security & disclosure

Clear access boundaries, preserved evidence and responsible reporting.

Document version · 2026-10-03

Separate security zones

The marketing site is unauthenticated and exposes no tenant evidence, billing controls or internal tools. Customer sessions are limited to the customer app and resolved to an authorised tenant on the server. Internal staff operations have their own session audience, mandatory MFA, roles and audit stream. Hiding a navigation link is not an access control.

Evidence and access

Raw payloads are stored unchanged with SHA-256 hashes, timestamps and provenance. Normalised evidence is separately hashed. Verification checks integrity after capture and does not prove source truth. Customer access requires tenant membership, permission and entitlement checks. Staff evidence access must be explicit, reason-required, time-limited and audited.

Reporting a suspected vulnerability

Use the contact form to request a private security-reporting channel. Put “Security report” in the message and include a business contact, the affected public URL and a brief non-sensitive description. Do not submit passwords, tokens, customer evidence, exploit payloads or personal data. A dedicated security mailbox and response targets are awaiting confirmation; this page does not claim a monitored emergency-response service.

Request security contact →

Safe reporting boundaries

Only test systems you own or are expressly authorised to test. Do not access another tenant’s data, disrupt services, persist access, exfiltrate evidence or contact customers. Stop if sensitive information is encountered and report only the minimum detail needed through an agreed private channel. This policy does not grant permission for intrusive testing or promise a bounty, legal safe harbour or response SLA.

Disclosure and verification

Coordinate reproduction, remediation and public disclosure privately. A report should distinguish observed impact from speculation. Do not publish sensitive evidence or credentials. Machine-readable reporting information is available at /.well-known/security.txt. No PGP key, certification or external security endorsement is claimed without verified details.

Service emergencies

Existing customers should use the incident and support channels agreed in their service contract. The public enquiry form is not an emergency incident-response channel.