Toutmark

Security Disclosure Policy

Effective: April 23, 2026 | Last Updated: May 31, 2026
Legal Disclaimer: Toutmark is not your lawyer. This document is drafted pragmatically but has not been reviewed by counsel. Before onboarding enterprise customers or processing large volumes of EU/UK data, Toutmark will commission a legal review. Customers should consult their own counsel about whether these terms work for their use case.

Toutmark welcomes responsible security disclosures from researchers and security professionals. This policy explains how to report vulnerabilities and what to expect in response.

1. Responsible Disclosure Invitation

Toutmark invites security researchers and ethical hackers to report vulnerabilities in the Toutmark platform. We believe in transparency and will work cooperatively with researchers to fix issues.

Our Commitment

If you follow this policy, Toutmark commits to:

2. In-Scope

Please report vulnerabilities in the following:

3. Out-of-Scope

Do NOT test or report issues in the following:

4. How to Report a Vulnerability

Email: [email protected]

Subject Line: "[SECURITY] Vulnerability Report — [Brief Title]"

What to Include

  1. Vulnerability Type: SQL injection, XSS, CSRF, authentication bypass, etc.
  2. Affected Endpoint or Feature: URL, API endpoint, or feature name
  3. Reproduction Steps: Detailed, step-by-step instructions to reproduce the issue
  4. Expected vs. Actual Behavior: What should happen vs. what actually happens
  5. Impact Assessment: What could an attacker do with this vulnerability?
  6. Screenshots or PoC: If applicable, attach evidence (screenshots, video, or proof-of-concept code)
  7. Your Contact Information: Name, email, PGP key (if you want encrypted communication)

Do NOT Include

5. Response Timeline

6. Safe Harbor & Legal Protection

Good-Faith Researchers: If you follow this policy and act in good faith, Toutmark will not pursue legal action against you for:

Conditions: This safe harbor applies only if you:

7. Bug Bounty Program

Live Phase: Toutmark does not currently offer a paid bug bounty program. However, we do offer:

Future Phases: As Toutmark grows, we may implement a formal paid bug bounty program. Security researchers who have helped us will be notified of any bounty offering.

8. Disclosure Policy

Coordinated Disclosure

We follow a coordinated disclosure timeline:

Public Acknowledgment

Once a fix is deployed, Toutmark will publish a security advisory that includes:

9. Security Contact

Security Email: [email protected]

Mailing Address:
Toutmark
2712 N Ardmore Avenue
Manhattan Beach, CA 90266
USA

PGP Key:

10. Security Best Practices

While you're researching, please follow these best practices:

Version History: