Trisotech · Vulnerability Disclosure

Trisotech Vulnerability Disclosure

Vulnerability disclosure

Trisotech runs a coordinated vulnerability disclosure program on Hackerone.

Business Process ManagementDecision ManagementWorkflow AutomationLow CodeBPMNDMNCMMNHealthcareFHIRClinical Decision SupportStandardsAI AgentsModel Context ProtocolEnterprise Architecture
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

trisotech-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-02'
method: searched
source: https://www.trisotech.com/security/
name: Trisotech vulnerability disclosure
summary: >-
  Trisotech names a route for reporting a security incident, but it is prose on a marketing
  page pointing at a general contact form — not a security.txt, not a dedicated security
  address, and not a bug bounty. A researcher can reach the company; they cannot find the
  route from any machine-readable location, and there is no published safe-harbour or
  response commitment.
policy_published: false
policy_url: https://www.trisotech.com/security/
statement: >-
  "If you would like to send a security incident report to Trisotech anonymously or using
  your contact information, please use our Contact us page"
reporting_channels:
  - type: web-form
    url: https://www.trisotech.com/contact-us/
    http_status: 200
    anonymous_accepted: true
    note: >-
      The general company contact form, shared with sales enquiries. Trisotech explicitly
      allows an anonymous report through it.
  - type: email
    address: sales@trisotech.com
    note: >-
      The only email address published on the security page is the sales address. There is
      no security@ or psirt@ address published anywhere on the site.
  - type: telephone
    numbers:
      - 1-877-374-3995
      - 514-990-6639
security_txt:
  served: false
  probed_hosts:
    - www.trisotech.com
    - cloud.trisotech.com
  status: 404
  ref: well-known/trisotech-well-known.yml
bug_bounty:
  program: none
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  found: false
commitments:
  safe_harbour: false
  response_sla: false
  disclosure_timeline: false
  cve_publication: false
  advisories_page: false
  note: >-
    None of these is published. Security fixes do appear in the release notes, but only as
    the undifferentiated line "Security updates." with no severity, no CVE and no advisory.
gaps_for_the_provider_to_close:
  - Serve /.well-known/security.txt (RFC 9116) on www.trisotech.com and cloud.trisotech.com.
  - Publish a security@trisotech.com address distinct from sales.
  - State a safe-harbour and an acknowledgement window.
evidence:
  - url: https://www.trisotech.com/security/
    status: 200
  - url: https://www.trisotech.com/contact-us/
    status: 200
  - url: https://www.trisotech.com/.well-known/security.txt
    status: 404
  - url: https://cloud.trisotech.com/.well-known/security.txt
    status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/trisotech-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.