Responsible Disclosure
Responsible Disclosure
We take the security of our platform and our customers' data seriously. If you believe you have found a security vulnerability in Tropico Security's systems, we want to hear from you.
How to report
Send your report to info [at] tropicosecurity.com. Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce, including any proof-of-concept code, requests, or screenshots
- The affected URL, endpoint, or component
- Your contact details, and how you would like to be credited if the issue is confirmed
We will acknowledge your report within 3 business days and keep you informed as we investigate. We aim to validate and triage reports within 10 business days.
Scope
In scope: systems and applications operated by Tropico S.r.l. on domains we own, including tropicosecurity.com and our production platform.
Out of scope:
- Deception assets. Our products deploy decoy portals, honeypots, and lures by design. Findings against systems that are intentionally vulnerable are not vulnerabilities.
- Customer-owned infrastructure and third-party services we do not operate
- Denial of service, volumetric, or resource-exhaustion testing
- Social engineering, phishing, or physical attacks against our staff or offices
- Reports generated solely by automated scanners without demonstrated impact
- Missing security headers, TLS configuration preferences, and similar findings with no practical exploit path
Rules of engagement
Please act in good faith. Do not access, modify, or exfiltrate data belonging to us or our customers; use only test accounts and your own data. Do not degrade the availability of our services. Give us a reasonable opportunity to remediate before disclosing publicly, and coordinate the timing of any publication with us.
Safe harbour
If you follow the rules above and report promptly and in good faith, we will not pursue legal action against you for your research, and we will treat your activity as authorised. This commitment does not extend to third parties, and it does not waive obligations you may have under applicable law.
Recognition and rewards
We maintain no fixed bounty schedule. Rewards are evaluated on a case-by-case basis, taking into account the severity and impact of the finding, the quality of the report, and whether the issue was previously known to us. With your permission, we are happy to credit researchers publicly for confirmed findings.
Awards:
Tropico is awarded the 2025 ANGI Oscar for Innovation
by Tinexta Cyber



Our Certifications:



