Security Contact
Security reports need a clear inbox, a safe disclosure path, and honest status about keys and launch readiness.
Report a vulnerability
Send reproducible security issues to security@torna.io. Include affected component, impact, steps to reproduce, account/server ids if relevant, and whether the report is time-sensitive.
PGP is not published yet
Until a production PGP key is published, do not send private keys, exploit payloads, customer data, or highly sensitive proof in the first email. Send a low-detail summary, impact, and a safe way for the security owner to continue the report.
What to report
- Authentication bypass, token leakage, privilege escalation, or wallet/account takeover.
- Subscription link signing flaws, route handout exposure, or supplier isolation failures.
- Payment approval abuse, withdrawal bypass, settlement corruption, or audit-log tampering.
- Client-side leaks in iOS/browser import flows or third-party handoff pages.
Disclosure expectations
Do not access other users' data, run destructive tests, attack suppliers, or publish exploit details before operators have had time to mitigate. Good-faith reports should not be penalized.
Launch readiness
Before advertising, Torna still needs the production security inbox, published PGP key, attestation decision, backup/restore drill, and incident runbook rehearsal.
Safe first-contact templates
Copy a safe first report
Use this packet when you need to contact security before PGP is published. It gives the security owner enough context to triage without sending exploit material or sensitive data in the first message.
- Report type
- security vulnerability / account takeover / payment bypass / active safety issue
- Affected surface
- web / gateway API / subscription link / supplier server / payment / client import
- Impact
- what could go wrong, without exploit detail
- Production reproduced
- yes / no / not tested
- Safe reference ids
- account/server/session/order id prefixes only, if relevant
- Safe contact path
- email, Telegram handle, or other callback path
- Sensitive details held back
- yes - I need PGP or another secure channel before sending proof
Keep the first message low-detail
Do not include private keys, cloud tokens, OTP codes, passwords, exploit payloads, customer data, full logs, payment proofs, or screenshots with unrelated personal information until a secure channel is confirmed.