Torna

Sign in
securityPGP publication pending before launch

Security Contact

Security reports need a clear inbox, a safe disclosure path, and honest status about keys and launch readiness.

Report a vulnerability

Send reproducible security issues to security@torna.io. Include affected component, impact, steps to reproduce, account/server ids if relevant, and whether the report is time-sensitive.

PGP is not published yet

Until a production PGP key is published, do not send private keys, exploit payloads, customer data, or highly sensitive proof in the first email. Send a low-detail summary, impact, and a safe way for the security owner to continue the report.

What to report

  • Authentication bypass, token leakage, privilege escalation, or wallet/account takeover.
  • Subscription link signing flaws, route handout exposure, or supplier isolation failures.
  • Payment approval abuse, withdrawal bypass, settlement corruption, or audit-log tampering.
  • Client-side leaks in iOS/browser import flows or third-party handoff pages.

Disclosure expectations

Do not access other users' data, run destructive tests, attack suppliers, or publish exploit details before operators have had time to mitigate. Good-faith reports should not be penalized.

Launch readiness

Before advertising, Torna still needs the production security inbox, published PGP key, attestation decision, backup/restore drill, and incident runbook rehearsal.

Safe first-contact templates

Copy a safe first report

Use this packet when you need to contact security before PGP is published. It gives the security owner enough context to triage without sending exploit material or sensitive data in the first message.

Report type
security vulnerability / account takeover / payment bypass / active safety issue
Affected surface
web / gateway API / subscription link / supplier server / payment / client import
Impact
what could go wrong, without exploit detail
Production reproduced
yes / no / not tested
Safe reference ids
account/server/session/order id prefixes only, if relevant
Safe contact path
email, Telegram handle, or other callback path
Sensitive details held back
yes - I need PGP or another secure channel before sending proof

Keep the first message low-detail

Do not include private keys, cloud tokens, OTP codes, passwords, exploit payloads, customer data, full logs, payment proofs, or screenshots with unrelated personal information until a secure channel is confirmed.