Responsible Disclosure Policy

Tirugo takes security reports seriously. This policy describes how you can report vulnerabilities in our systems in a responsible manner.

Scope

The following assets are in scope:

Out of scope:

Your commitments

When reporting a vulnerability we ask you to:

Our commitments

We commit to:

Bug bounty

Tirugo does not currently operate a public bug-bounty programme. In selected cases we acknowledge outstanding reports individually (vouchers, credits, invitations to private beta programmes). Monetary rewards are not guaranteed.

How to report

Send an email – preferably encrypted – to: security@tirugo.ch

PGP key fingerprint: available on request.

Please include:

Machine-readable

Security contact per RFC 9116: /.well-known/security.txt

Last updated: 17 April 2026