TROVE

TROVE

← Back to TROVE

Security & Responsible Disclosure

Last updated: 29 May 2026
Short version: If you've found a security issue in Trove, please tell us before telling the internet. Email trovefi-support@googlegroups.com and we will respond within 3 business days. We do not sue, threaten, or report good-faith researchers.

1. How we handle your data

Trove was built privacy-first. The detail lives in the Privacy Policy, but the summary that matters for security is:

2. Reporting a vulnerability

Email trovefi-support@googlegroups.com with:

Please do not exploit the issue beyond what's needed to confirm it, and please don't access data that isn't yours. Don't publicly disclose the issue until we've had a reasonable chance to fix it (we aim for 30 days for high-severity, 90 days for everything else).

Email
Response SLA
Acknowledgement within 3 business days
Disclosure
Coordinated; 30 / 90 day target depending on severity

3. Scope

In scope:

Out of scope:

4. What we promise

5. Hall of fame

Coming soon. We'll credit the first valid disclosure here with the reporter's name and link (if they want it public).

6. Production controls (overview)