Trust
Security at Encipher Trust
As a security company, we hold ourselves to the standards we recommend to clients. If you believe you have found a vulnerability in our website or services, we want to hear from you.
Philosophy
Our security principles
- 01
Least privilege
Access to systems and data is limited to what each role requires.
- 02
Defence in depth
Layered controls so no single failure exposes customer data.
- 03
Data minimisation
We collect only what we need and retain it only as long as necessary.
- 04
Transparency
We disclose security issues responsibly and communicate clearly.
Responsible disclosure
Vulnerability reporting process
We support good-faith security research and will not pursue legal action against researchers who follow this policy.
-
Report
Email security@enciphertrust.com with a description, affected URL and reproduction steps.
-
Acknowledge
We aim to acknowledge reports within three business days.
-
Investigate
We validate the issue, assess impact and keep you informed of progress.
-
Resolve & credit
We fix confirmed issues and, with your permission, credit you for the finding.
Scope
Guidelines for researchers
Please do
- Test only against enciphertrust.com and services we own
- Use test data and your own accounts only
- Give us reasonable time to remediate before public disclosure
- Include clear reproduction steps and impact in your report
Please do not
- Perform denial-of-service, load or volumetric testing
- Access, modify or delete data that is not yours
- Use social engineering, phishing or physical attacks
- Submit automated scanner output without validation
Security contact: security@enciphertrust.com
Machine-readable contact details are published at /.well-known/security.txt (RFC 9116). Please do not include sensitive personal data in reports.