Trust & Security

Vulnerability Disclosure Policy

Guidelines for good-faith reporting of potential security vulnerabilities

Effective: August 3, 2026Last updated: August 3, 2026

How to Report

Email security@tritontelephone.com with the affected service, reproduction steps, impact, date discovered and contact information.

Good-Faith Testing

  • Use only accounts and data you are authorized to access.
  • Stop if customer data is exposed.
  • Avoid privacy violations, disruption and destruction.
  • Allow reasonable investigation time before disclosure.

Testing Not Authorized

  • Denial-of-service or load testing.
  • Social engineering or phishing.
  • Physical attacks.
  • Malware deployment or persistence.
  • Accessing or modifying customer data.
  • Testing third-party systems outside Triton’s control.

Response Expectations

Triton reviews good-faith vulnerability reports and will acknowledge reports when reasonably practical. Response and remediation times depend on severity, complexity and affected systems.

Safe Harbor

Triton does not authorize unlawful activity or waive any legal rights. Triton will consider the circumstances and good-faith nature of research when evaluating reports submitted under this policy.

Contact

Legal questions: legal@tritontelephone.com. Privacy: privacy@tritontelephone.com. Security: security@tritontelephone.com.