Security

Security and vulnerability disclosure

How to report a security issue in Tripticonsent, and what you can expect from us.

Reporting a vulnerability

Email dp@tripticode.com with a description of the issue, the steps to reproduce it, and the impact you believe it has. Please do not open a public issue or share the details with anyone else until we have fixed it. Our machine-readable contact details are at `/.well-known/security.txt`.

What we commit to

  • We acknowledge your report within 3 business days.
  • We keep you informed while we investigate and fix it, and tell you when the fix is deployed.
  • We credit you publicly once it is fixed, if you want us to.
  • We will not take legal action against research carried out in good faith within the scope below.

Scope

In scope: tripticonsent.tripticode.com, console.tripticonsent.tripticode.com, api.tripticonsent.tripticode.com, the MCP server, the hosted consent banner (cmp.js), and the published SDKs and plugins.

  • Only test against organizations and sites you own, and use TEST mode keys.
  • Never access, modify or delete other customers' data. If you reach any by accident, stop, and tell us what you saw.
  • No denial-of-service testing, load testing, spam or social engineering of our staff or customers.
  • Out of scope: findings that need a compromised device, missing security headers with no demonstrated impact, and reports from automated scanners without a working proof.