TRUSTVAULT
Back to TrustVault

Security reporting

Responsible Disclosure

A clear path for reporting potential security issues without exposing wallet secrets or creating unnecessary risk.

Last updated: 24 August 2026

Reporting a potential vulnerability

If a potential TrustVault security issue is discovered, report it privately through the current published email contact before sharing technical details publicly.

  • Email: marvellgregory85@gmail.com
  • Describe the affected page, route, component or transaction flow.
  • Provide clear reproduction steps where doing so does not put customers, wallets or third parties at risk.
  • Explain the observed behavior and the expected behavior.
  • Include a public transaction hash or public blockchain reference only when relevant.

Do not send wallet secrets

A security report must never include a private key, seed phrase, recovery phrase, password or signing credential.

TrustVault does not require wallet secrets in order to review a security report.

Please avoid harmful testing

Security research should avoid accessing another person's private data, disrupting availability, attempting unauthorized fund movement or deliberately creating harm.

If testing could affect another customer, wallet, seller or service, stop and report the issue using the available contact channel.

Useful report details

  • Affected URL or TrustVault feature.
  • Browser, wallet and device information when relevant.
  • Steps needed to reproduce the behavior.
  • Screenshots that do not expose secrets.
  • Relevant public transaction or explorer references.
  • A concise explanation of potential impact.

Disclosure expectations

Please allow reasonable time for an issue to be reviewed and addressed before publishing vulnerability details that could put customers or systems at risk.

TrustVault may request additional non-sensitive technical information when needed to reproduce the report.

Current program status

This page provides a responsible reporting path. It does not represent a bug bounty, paid reward program, security certification or independent security audit.

No reward, payment or recognition should be assumed unless it has been explicitly agreed separately.