Trisotech · Vulnerability Disclosure
Trisotech Vulnerability Disclosure
Vulnerability disclosure
Trisotech runs a coordinated vulnerability disclosure program on Hackerone.
Business Process ManagementDecision ManagementWorkflow AutomationLow-CodeBPMNDMNCMMNHealthcareFHIRClinical Decision SupportStandardsAI AgentsMCPEnterprise Architecture
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-02'
method: searched
source: https://www.trisotech.com/security/
name: Trisotech vulnerability disclosure
summary: >-
Trisotech names a route for reporting a security incident, but it is prose on a marketing
page pointing at a general contact form — not a security.txt, not a dedicated security
address, and not a bug bounty. A researcher can reach the company; they cannot find the
route from any machine-readable location, and there is no published safe-harbour or
response commitment.
policy_published: false
policy_url: https://www.trisotech.com/security/
statement: >-
"If you would like to send a security incident report to Trisotech anonymously or using
your contact information, please use our Contact us page"
reporting_channels:
- type: web-form
url: https://www.trisotech.com/contact-us/
http_status: 200
anonymous_accepted: true
note: >-
The general company contact form, shared with sales enquiries. Trisotech explicitly
allows an anonymous report through it.
- type: email
address: sales@trisotech.com
note: >-
The only email address published on the security page is the sales address. There is
no security@ or psirt@ address published anywhere on the site.
- type: telephone
numbers:
- 1-877-374-3995
- 514-990-6639
security_txt:
served: false
probed_hosts:
- www.trisotech.com
- cloud.trisotech.com
status: 404
ref: well-known/trisotech-well-known.yml
bug_bounty:
program: none
platforms_checked: [HackerOne, Bugcrowd, Intigriti]
found: false
commitments:
safe_harbour: false
response_sla: false
disclosure_timeline: false
cve_publication: false
advisories_page: false
note: >-
None of these is published. Security fixes do appear in the release notes, but only as
the undifferentiated line "Security updates." with no severity, no CVE and no advisory.
gaps_for_the_provider_to_close:
- Serve /.well-known/security.txt (RFC 9116) on www.trisotech.com and cloud.trisotech.com.
- Publish a security@trisotech.com address distinct from sales.
- State a safe-harbour and an acknowledgement window.
evidence:
- url: https://www.trisotech.com/security/
status: 200
- url: https://www.trisotech.com/contact-us/
status: 200
- url: https://www.trisotech.com/.well-known/security.txt
status: 404
- url: https://cloud.trisotech.com/.well-known/security.txt
status: 404
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/trisotech-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.