Trivian Technologies takes security reports seriously, particularly where they affect authorization, provenance, auditability, data exposure, or autonomous execution.
Do not open a public GitHub issue for a suspected security vulnerability.
Send a private report to node@triviantech.com with:
- the affected repository and version or commit;
- a concise description of the issue;
- reproduction steps or proof of concept, when safe to provide;
- the potential impact;
- any suggested mitigation.
Please avoid accessing data that is not yours, degrading services, or expanding a proof of concept beyond what is necessary to demonstrate the issue.
Repositories in this organization have different maturity levels. A repository being public does not imply production deployment or a security warranty. Check the repository README and release documentation for its current status.
We will assess reports according to severity, reproducibility, affected surface, and current deployment status. Where appropriate, remediation may include code changes, documentation changes, release notes, revocation of affected authority, or coordinated disclosure.