generated: '2026-09-18' method: searched probe: true source: https://www.trustly.com/security/disclosure url: https://www.trustly.com/security/disclosure program: Responsible disclosure (self-run; no HackerOne/Bugcrowd/Intigriti program found — hackerone.com/trustly returns 404) contact: security@trustly.com pgp: a public PGP key is offered for encrypted reports (the page says "we prefer that you encrypt the report with our public PGP key") scope: domains or IP addresses owned by Trustly Group AB or Trustly Inc. (verify with WHOIS) out_of_scope: - non-200 HTTP pages, banner/fingerprint disclosure, robots.txt-style public files - clickjacking, logout CSRF, CSRF on anonymous forms, autocomplete/save-password flags - missing security headers (HSTS, X-Frame-Options, CSP and friends), TLS issues such as BEAST/BREACH/weak ciphers - email configuration (DMARC, SPF, DKIM), weak password policies, content spoofing without HTML/CSS - enumeration of @trustly.com addresses, OPTIONS method enabled rules: - good-faith testing only, inside your own account or with written consent of the account owner - no automated scans, no physical or social-engineering tests, no DoS/DDoS - no public or third-party disclosure without Trustly's explicit permission hall_of_fame: true bounty: not stated (a Hall of Fame is offered "as a token of appreciation") security_txt: probed: https://www.trustly.com/.well-known/security.txt status: 404 note: no RFC 9116 security.txt on www.trustly.com, trustly.one, api.trustly.com, amer.developers.trustly.com or docs.trustly.com evidence: - source: https://www.trustly.com/security/disclosure status: 200 kind: disclosure page keywords: - responsible disclosure - security@trustly.com - hall of fame - source: https://www.trustly.com/security status: 200 kind: security overview page linking to /security/disclosure