Skip to content
TRUETOTAL · LEGAL & TRANSPARENCY

Security & Responsible Disclosure

EFFECTIVE 3 AUGUST 2026

If you have found a security problem in TrueTotal, thank you — we want to hear about it, and we would rather hear it from you than from an incident. This page tells you how to report it and what we commit to in return.

REPORT IT HERE
Email security@truetotalcalculator.com with what you found and how to reproduce it. We acknowledge within two working days. Please give us a reasonable chance to fix it before disclosing publicly — and we commit, in return, to the safe harbour set out below.

Our safe-harbour commitment

If you act in good faith under this policy, we will treat your research as authorised. Specifically, we will not pursue legal action, report you to law enforcement, or ask your hosting provider to suspend you for security research that:

  • stays within the scope below;
  • avoids privacy violations, data destruction, and degradation of the service for others;
  • uses only the minimum access needed to demonstrate the issue, and stops as soon as it is demonstrated;
  • does not access, copy, retain or disclose data belonging to other people;
  • gives us a reasonable period to remediate before public disclosure.

If you are unsure whether something is in scope, ask first at security@truetotalcalculator.com. Asking never counts against you.

What to include in a report

  • The affected URL, endpoint or component.
  • Clear reproduction steps — the shorter the path to reproducing it, the faster the fix.
  • What an attacker could actually achieve, and how you assess the impact.
  • Any proof-of-concept, logs or screenshots (with other people’s data redacted).
  • How you would like to be credited, if you want to be.

In scope

  • The TrueTotal website and its public API.
  • The outbound click redirect (/go) — open-redirect and tracking-integrity issues especially.
  • Authentication and authorisation on any operator or partner endpoint.
  • Injection, cross-site scripting, request forgery, access-control and data-exposure issues.
  • Anything that could expose personal data, click data or attribution records.

Out of scope

  • Third-party sites we link to — report those to their owners; we will help route it if you tell us.
  • Findings from automated scanners with no demonstrated exploitability.
  • Volumetric denial-of-service, load testing or resource-exhaustion attacks. Please do not run these.
  • Social engineering of our people, partners or suppliers; physical attacks.
  • Missing hardening headers or best-practice suggestions with no demonstrated impact (still welcome as feedback, just not treated as vulnerabilities).
  • Issues requiring a compromised device, a rooted browser, or a highly improbable user interaction.

What we do when you report

  • Acknowledge within 2 working days.
  • Triage and initial assessment within 5 working days, with our view of severity and an indicative timeline.
  • Fix critical issues urgently — typically within days, and we will keep you updated rather than going silent.
  • Tell you when it is fixed, and credit you publicly if you would like that.
  • Notify affected users and the relevant supervisory authority where a personal-data breach requires it, within the statutory timeframe.

No bounty — yet

TrueTotal is pre-revenue and does not currently run a paid bug-bounty programme. We will not pretend otherwise to attract reports. What we do offer is a fast, respectful response, public credit if you want it, and the safe harbour above. If that changes, this page will say so.

How we protect the service

In the interests of the same transparency we ask of others: the site runs on Cloudflare’s edge with HTTPS/HSTS enforced, a strict Content-Security-Policy, security headers set at the edge, no third-party advertising or analytics scripts, and secrets held in the platform’s secret store rather than in the repository. Outbound redirects are constrained to an allow-list of partner domains. Click and attribution records are stored in a managed database with restricted access.

Some hardening is still outstanding before commercial launch — including WAF rules, global rate limiting and full monitoring. We would rather list that honestly than imply a maturity we have not reached. Our data-handling commitments are in the Privacy Policy and the Trust Center.

Contact

Security reports: security@truetotalcalculator.com. Data-protection concerns: privacy@truetotalcalculator.com. Please do not post vulnerability details in public channels or in an error report before contacting us.

← All legal & transparency documents