Security
Security and vulnerability disclosure
How to report a security issue in Tripticonsent, and what you can expect from us.
Reporting a vulnerability
Email dp@tripticode.com with a description of the issue, the steps to reproduce it, and the impact you believe it has. Please do not open a public issue or share the details with anyone else until we have fixed it. Our machine-readable contact details are at `/.well-known/security.txt`.
What we commit to
- We acknowledge your report within 3 business days.
- We keep you informed while we investigate and fix it, and tell you when the fix is deployed.
- We credit you publicly once it is fixed, if you want us to.
- We will not take legal action against research carried out in good faith within the scope below.
Scope
In scope: tripticonsent.tripticode.com, console.tripticonsent.tripticode.com, api.tripticonsent.tripticode.com, the MCP server, the hosted consent banner (cmp.js), and the published SDKs and plugins.
- Only test against organizations and sites you own, and use TEST mode keys.
- Never access, modify or delete other customers' data. If you reach any by accident, stop, and tell us what you saw.
- No denial-of-service testing, load testing, spam or social engineering of our staff or customers.
- Out of scope: findings that need a compromised device, missing security headers with no demonstrated impact, and reports from automated scanners without a working proof.