Trust

Security at Encipher Trust

As a security company, we hold ourselves to the standards we recommend to clients. If you believe you have found a vulnerability in our website or services, we want to hear from you.

Philosophy

Our security principles

  • 01

    Least privilege

    Access to systems and data is limited to what each role requires.

  • 02

    Defence in depth

    Layered controls so no single failure exposes customer data.

  • 03

    Data minimisation

    We collect only what we need and retain it only as long as necessary.

  • 04

    Transparency

    We disclose security issues responsibly and communicate clearly.

Responsible disclosure

Vulnerability reporting process

We support good-faith security research and will not pursue legal action against researchers who follow this policy.

  1. Report

    Email security@enciphertrust.com with a description, affected URL and reproduction steps.

  2. Acknowledge

    We aim to acknowledge reports within three business days.

  3. Investigate

    We validate the issue, assess impact and keep you informed of progress.

  4. Resolve & credit

    We fix confirmed issues and, with your permission, credit you for the finding.

Scope

Guidelines for researchers

Please do

  • Test only against enciphertrust.com and services we own
  • Use test data and your own accounts only
  • Give us reasonable time to remediate before public disclosure
  • Include clear reproduction steps and impact in your report

Please do not

  • Perform denial-of-service, load or volumetric testing
  • Access, modify or delete data that is not yours
  • Use social engineering, phishing or physical attacks
  • Submit automated scanner output without validation

Security contact: security@enciphertrust.com

Machine-readable contact details are published at /.well-known/security.txt (RFC 9116). Please do not include sensitive personal data in reports.