Security

Security reports
should have a clear path.

Trebell is early-stage, but that is not an excuse to make vulnerability reporting mysterious. This page explains how to report security issues and what the public website currently does.

Report a vulnerability

Email [email protected] with the subject prefix [SECURITY]. Include the affected component, reproduction steps, expected impact, and any proof-of-concept details that are safe to share.

Please avoid accessing other people's data, disrupting services, or publishing an issue before we have had a reasonable opportunity to investigate it.

Scope

Reports can cover the public Trebell websites, Trebell Code, release artifacts, or Trebell-owned infrastructure. Vulnerabilities in a third-party model provider or external service should normally be reported to that provider as well.

Website posture

The company site is primarily static. We found no analytics, advertising trackers, account system, or web forms in the current site. A theme preference may be stored locally in your browser. Hosting and font providers may receive ordinary request metadata needed to serve their resources.

Open-source review

Trebell Code's source is public under Apache-2.0, which means security-sensitive behavior in the flagship product can be inspected rather than hidden behind a marketing page.