Vulnerability Disclosure Policy
Introduction
Traken (operated by Headframe sp. z o.o.) welcomes reports from security researchers acting in good faith. This Vulnerability Disclosure Policy ("VDP") explains what we ask of you and what you can expect from us. This is not a bug-bounty programme: we do not offer monetary rewards, and this Policy is not the terms of a bug-bounty programme.
Scope
In scope: the traken.ai website and the Traken web application and its APIs operated by us. Out of scope: (a) services operated by our subprocessors or other third parties (e.g., Hetzner, Cloudflare, Supabase, Mistral, Anthropic, n8n, Paddle) — report those to the relevant provider under its own policy; (b) findings without a realistic security impact (e.g., missing best-practice headers, version banners, self-XSS, rate-limit-only issues); and (c) social engineering, phishing, physical attacks, and denial-of-service or load testing, which are not authorised.
Rules of engagement
Please: only test accounts and data that belong to you; do not access, modify, delete, or exfiltrate data that is not yours; stop immediately and notify us if you encounter personal data or other sensitive information; use exploits only to the minimum extent needed to confirm a vulnerability, and do not pivot, establish persistence, or exfiltrate data; and never degrade, disrupt, or overload the Service.
How to report
Email security@traken.ai with a description of the issue, the affected URL/endpoint, steps to reproduce, and the impact. If you wish to encrypt your report, request our PGP key at that address.
Response commitments
We aim to acknowledge your report within 3 business days, provide a triage assessment within 10 business days, and keep you reasonably updated on remediation of valid reports. We will credit researchers who wish to be named once an issue is resolved, where disclosure is coordinated with us. Please give us a reasonable time to remediate before any public disclosure and coordinate timing with us.
Safe harbour
If you make a good-faith effort to comply with this Policy during your research, we will consider your security research to be authorised, we will not initiate or support legal action against you for that research, and we will work with you to understand and resolve the issue quickly. If a third party initiates legal action against you for activities conducted in accordance with this Policy, we will make this authorisation known. This Policy does not authorise activity that violates applicable law, and nothing in it waives any rights of third parties. If in doubt whether a specific test is authorised, contact us first at security@traken.ai.