Trailblaze Solutions LLC d/b/a Trailblaze Data welcomes reports from security researchers. If you believe you have found a vulnerability in our website, API, or Services, this page tells you how to tell us and what you can expect from us in return.
This page is our disclosure policy. The security measures we commit to are set out in Annex II of our Data Processing Agreement.
1. How to Report
Email security@trailblazedata.com. If you do not receive an acknowledgement within three business days, follow up to legal@trailblazedata.com or call 888-628-9316.
A useful report includes:
- The affected URL, endpoint, or parameter
- The type of issue, and its impact if exploited
- Steps to reproduce it, including any request or payload needed
- Any proof-of-concept output, screenshots, or logs
- Whether you accessed, altered, or retained any data, and what you did with it
- How you would like to be credited, if you would like to be
Report in English where you can. You may report anonymously, though it makes it harder for us to ask follow-up questions or credit you.
2. What We Commit To
| Acknowledgement | Within 3 business days of receiving your report |
|---|---|
| Initial assessment | Within 10 business days, including whether we can reproduce the issue and how we have rated its severity |
| Progress updates | At least every 14 days while the issue is open |
| Remediation target | Critical and high severity issues prioritized immediately; other issues scheduled according to risk, and we will tell you the plan |
| Resolution notice | We tell you when the issue is fixed, and confirm if you would like to retest |
| Credit | We will credit you publicly if you want us to, once the issue is resolved |
We do not currently operate a paid bug bounty, so we cannot offer a monetary reward. We say so plainly rather than leaving it open.
If a vulnerability has affected customer data, we will handle notification as described in section 14 of our Data Processing Agreement and section 10 of our Privacy Policy.
3. Safe Harbour
If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, we will:
- Not pursue or support civil or criminal action against you in connection with your research
- Treat your research as authorized under the Computer Fraud and Abuse Act, comparable state law, and the anti-circumvention provisions of the Digital Millennium Copyright Act, to the extent it is within our power to do so
- Waive any claim under the Terms of Use that your research breached the restrictions on unauthorized access or testing
- Work with you if a third party pursues you for research conducted under this policy, and make clear that it was authorized
This authorization extends only to systems we operate. It cannot cover the systems of our providers, our customers, or any third party, and it does not apply to conduct outside the rules in section 4.
4. Rules of Engagement
Please:
- Test only against accounts and data you own or have explicit permission to use
- Stop as soon as you have confirmed a vulnerability, and do not go further into the system than needed to demonstrate it
- Use the minimum data necessary to prove the issue, and delete any customer data you encounter as soon as you have reported it
- Give us reasonable time to fix an issue before disclosing it publicly. We ask for 90 days from your report, or until a fix ships if sooner, and we will work with you on the timing.
- Report promptly rather than accumulating findings
Please do not:
- Access, modify, exfiltrate, or retain data belonging to another customer or individual
- Run denial-of-service, volumetric, or stress tests, or anything that degrades the Services for others
- Send unsolicited email, phish, or social-engineer our staff, customers, or providers
- Attempt physical access to our premises or those of our providers
- Install a backdoor, persistence mechanism, or malware
- Use automated scanners at a rate that affects availability
- Demand payment in exchange for withholding or disclosing a finding
5. Scope
In scope: trailblazedata.com and its subdomains, our public API, and the signed-in product, to the extent we operate them.
Out of scope, unless you can demonstrate a concrete exploitable impact:
- Findings from automated scanners submitted without validation
- Missing security headers or cookie flags with no demonstrated impact
- Reports about email authentication records such as SPF, DKIM, and DMARC, absent a working spoofing proof
- Rate limiting on unauthenticated endpoints, absent a demonstrated impact
- Clickjacking or tabnabbing on pages with no sensitive action
- Self-inflicted cross-site scripting requiring the victim to paste a payload
- Vulnerabilities requiring a rooted device, a physically compromised machine, or a heavily outdated browser
- Social engineering, phishing, or physical attacks
- Denial of service and volumetric attacks
- Issues in third-party services we do not operate, which should go to that provider
- Verification results you disagree with, which are a support matter rather than a security issue
6. Machine-Readable Contact
Our security contact is also published at /.well-known/security.txt, in the format described by RFC 9116.
7. Not a Security Issue?
For account problems, billing questions, or help using the Services, contact support@trailblazedata.com. For privacy requests, see section 12 of our Privacy Policy. For abuse of our Services by another user, email legal@trailblazedata.com with the details.
8. Contact
Trailblaze Solutions LLC d/b/a Trailblaze Data
2500 Morris Ave, 1st Floor
Union, NJ 07083
United States
Security reports: security@trailblazedata.com
Legal: legal@trailblazedata.com
Phone: 888-628-9316