Trust
Security and Vulnerability Reporting
Last reviewed: August 19, 2026
Current scope
This page covers the static public Vortiek website. The Vortiek product and apps are prelaunch and do not currently accept accounts, payments, loyalty credentials, or travel records through this site.
Public-site safeguards
- HTTPS-only delivery with HTTP Strict Transport Security; plain HTTP redirects to the canonical HTTPS origin, and TLS certificates are issued and rotated automatically by our delivery providers.
- A restrictive Content Security Policy with no inline script execution, plus referrer and permissions policies, delivered on every response.
- No live public-site database, checkout, password login, or file upload.
- Optional analytics remains off until consent and uses an environment-supplied public key.
- Dependency, secret, and static-analysis checks run in continuous integration on every change and must pass before changes merge to the production branch.
No system is perfectly secure. We validate controls in proportion to this site's current static scope and will complete a separate threat model before product launch. We keep the identities of our infrastructure providers in an internal register; a current provider list is available to customers and security reviewers on request to legal@trunnion.ai.
Incident response and breach notification
We maintain an internal incident response plan with severity tiers, a named incident owner and deputy, and defined escalation and communication steps. It is paired with a breach notification procedure that assigns the notification decision to an accountable owner and tracks the statutory notification deadlines that would apply by data type and location. The disclosure channel below is the public entry point into that process.
Attestation roadmap
No certification or third-party attestation is claimed today, and none should be inferred from this page. Our attestation path targets SOC 2 (Security, Availability, and Confidentiality) and is sequenced to product stages rather than calendar dates: control design mapped to the SOC 2 Trust Services Criteria during prelaunch, which is in progress through our internal compliance registers and release gates; an independent readiness assessment before the authenticated product accepts traveler data; a SOC 2 Type I report at commercial launch; and a SOC 2 Type II report after the first full observation window following launch. This section is updated as stages complete.
Report a vulnerability
Email security@trunnion.ai with the affected URL, impact, reproducible steps, and contact information. Do not include active credentials, personal data, or destructive proof. We ask researchers to avoid privacy violations, service disruption, social engineering, and accessing more data than necessary.
We aim to acknowledge credible reports within five business days, provide a status update within ten business days, and coordinate remediation and disclosure based on severity. Good-faith research following these rules will not trigger legal action by us.
