Security and responsible disclosure
Last updated October 9, 2026
Reporting an issue
If you believe you have found a security vulnerability in terravoss.com or in anything Terravoss has built, please email security@terravoss.com. Our contact details are also published in security.txt.
What to include
- A description of the issue and where you found it
- Steps to reproduce it, or a proof of concept
- The impact you think it could have
- How we can reach you for follow-up questions
What you can expect from us
- An acknowledgment within two business days
- Regular updates while we investigate and fix the issue
- Credit for your report, if you would like it, once the issue is resolved
Good faith research
We will not pursue action against anyone who reports an issue in good faith, avoids privacy violations and service disruption, does not access or change data beyond what is needed to show the issue, and gives us reasonable time to fix it before sharing details publicly.
Out of scope
- Denial of service and load testing
- Social engineering of Terravoss or its clients
- Systems belonging to our clients or service providers