Our approach
Our security commitment
Trivixx Technologies Private Limited is committed to protecting the confidentiality, integrity, and availability of the systems and information under our control.
Our security practices are designed to evolve alongside our products, infrastructure, customer requirements, and the broader threat landscape.
We avoid absolute claims about security. Instead, we focus on practical risk reduction, responsible engineering, appropriate access controls, timely maintenance, and clear incident response.
Responsible disclosure
Report a security vulnerability
If you believe you have discovered a security vulnerability affecting a Trivixx product, service, website, or system, please report it privately to:
security@trivixx.comPlease do not publicly disclose the issue before we have had a reasonable opportunity to investigate and address it.
What to include in your report
- The affected product, service, website, or endpoint
- A clear description of the vulnerability
- Steps required to reproduce the issue
- The potential security impact
- Screenshots, logs, or proof of concept where appropriate
- Your preferred contact details
What happens next
How we handle security reports
Report received
Your report is received by the Trivixx security contact.
Acknowledgement
We aim to acknowledge valid reports within two business days.
Assessment
We review reproducibility, impact, affected systems, and severity.
Investigation and remediation
The relevant team investigates and prepares appropriate corrective action.
Resolution
Where appropriate, we coordinate the fix and communicate the outcome.
These are target response stages. Actual timelines may vary depending on complexity, severity, affected systems, and the availability of sufficient technical information.
Testing boundaries
Scope
In scope
- Trivixx websites and public web applications
- Trivixx-managed APIs and authentication systems
- TrivStay
- TrivRx
- TrivGo
- TrivStone
- Other products explicitly operated by Trivixx
Out of scope
- Social engineering or phishing of employees, customers, or partners
- Physical attacks against Trivixx offices, staff, or infrastructure
- Denial-of-service, load, stress, or destructive testing
- Automated testing that causes excessive traffic or service disruption
- Spam, unsolicited messaging, or content-related complaints
- Vulnerabilities in third-party services not controlled by Trivixx
- Reports based only on outdated scanner output without demonstrated impact
Good-faith research
Safe harbour
Trivixx will not pursue legal action against individuals who conduct security research in good faith, comply with this policy, avoid privacy violations and service disruption, do not exploit vulnerabilities beyond what is reasonably necessary to demonstrate them, and provide us with reasonable time to investigate and remediate the reported issue.
This safe-harbour statement does not authorise unlawful activity, access to third-party data, destruction of data, extortion, denial-of-service testing, social engineering, or actions that create risk for our customers, employees, partners, or infrastructure.
Security practices
Our security principles
Secure development
Security considerations are incorporated into product design, engineering, testing, deployment, and maintenance.
Access control
Administrative and operational access is limited according to role, responsibility, and business need.
Data protection
We use appropriate technical and organisational measures to protect information handled by our systems.
Dependency monitoring
Software dependencies and infrastructure components are reviewed and updated as security issues are identified.
Infrastructure security
Our systems are configured with security, availability, monitoring, and maintainability in mind.
Continuous improvement
We review security practices as our products, operations, risks, and customer requirements evolve.
Products and updates
Product security
When a verified vulnerability affects a supported Trivixx product or service, we assess the potential impact and determine the appropriate corrective action.
Depending on the issue, remediation may include a software update, configuration change, infrastructure adjustment, operational mitigation, customer communication, or a combination of these measures.
Customers are responsible for applying updates, maintaining secure configurations, protecting credentials, and following applicable product guidance.
Contact the security team
For suspected vulnerabilities, security concerns, or questions about this policy, contact our security team.
security@trivixx.com