Trust

Responsible Disclosure Policy

We welcome reports from security researchers who help keep TrustDesk safe. This policy explains how to report a vulnerability and what you can expect from us.

Last updated: July 23, 2026

1. Introduction

If you believe you have found a security vulnerability in a TrustDesk system, we encourage you to report it to us responsibly so we can investigate and remediate it.

2. Safe harbor

We will not pursue or support legal action against researchers who act in good faith, comply with this policy, avoid privacy violations and service disruption, and give us a reasonable opportunity to remediate before any public disclosure.

3. Scope

This policy covers systems and domains owned and operated by TrustDesk, including trustdesk.net and the TrustDesk platform.

It does not cover customer workspaces, customer data, or third-party services. Please do not access, modify, or exfiltrate any data that is not yours.

4. Out of scope

The following are generally out of scope: denial-of-service attacks, social engineering, physical attacks, spam, and reports consisting solely of raw automated-scanner output without a demonstrated, exploitable impact.

5. How to report

Email security@trustdesk.com with a clear description of the issue, the affected system, and step-by-step details needed to reproduce it. Include any proof-of-concept material where relevant.

6. Researcher guidelines

Only test against in-scope systems, use test accounts where possible, avoid impacting other users, and stop as soon as you identify a vulnerability. Keep details confidential until we confirm remediation.

7. Our commitment

We will acknowledge your report, keep you updated on our progress, work to remediate valid issues in a timely manner, and — with your permission — credit you for your contribution.

8. Contact

Send reports and questions to security@trustdesk.com.