TrackProject is currently available by invitation only.
Trust & Compliance · Security & AI

Responsible Disclosure

Help us keep TrackProject safe. Report vulnerabilities through our coordinated-disclosure programme.

Versionv2.1Last updated2026-06-25Last audit2026-05-12
UK GDPREU GDPRCCPA / CPRAISO/IEC 27001:2022ISO/IEC 42001 (AI)SOC 2

Our promise

We acknowledge your report within two business days, keep you informed of progress, credit you in our security hall of fame if you wish, and never pursue legal action for good-faith security research conducted under this policy.

Scope

In scope: the production TrackProject web application (track-project.com and *.track-project.com), mobile clients, public APIs and Customer-facing infrastructure. Out of scope: third-party services we depend on, social-engineering attacks against employees or Customers, physical attacks, denial-of-service and any finding that requires a privileged Customer account the researcher does not own.

How to report

Email security@track-project.com with a clear reproduction, affected URL, expected vs actual behaviour and any proof-of-concept artefacts. Encrypt sensitive reports with our PGP key (fingerprint published on request).

Response timeline

Acknowledgement within 2 business days. Triage within 5 business days. Remediation depends on severity — critical issues are patched as quickly as safely possible, typically within 7 days; high within 30 days; medium within 90 days. We will keep reporters updated throughout.

Rewards & recognition

We currently operate a recognition-based programme: validated reports earn a credit in our security hall of fame and TrackProject merchandise. A monetary bug-bounty programme is on the roadmap.

Safe harbour

We will not bring legal action against researchers who stay within scope, avoid privacy violations and service disruption, give us reasonable opportunity to remediate, and act in good faith. We consider this policy a public authorisation under applicable computer-misuse statutes.

Questions about this document? Contact legal@track-project.com · Security: security@track-project.com

© 2026 TrackProject Ltd. Version 2.1 · Last updated 2026-06-25.

Version history

  • v2.12026-06-25Added rewards & recognition section and tightened scope language.
  • v2.02026-03-01Coordinated-disclosure programme launched.