Last Updated: March 2026
Effective Date: March 2026
Trua takes the security of the Trust Bureau platform and the privacy of credential holders seriously. We welcome responsible disclosure of security vulnerabilities.
If you discover a security vulnerability in the Trust Bureau platform, please report it to:
We will acknowledge your report within 48 hours and provide an initial assessment within 5 business days.
We ask that you:
The following systems are in scope for security research:
bureau.trua.cloud)/api/v1/bureau/*)/ttb/wallet/*)/ttb/issuer/*, /ttb/verifier/*, /ttb/bureau/*)/ttb/*)@trua/issuer-sdk, @trua/holder-sdk, etc.)The following are out of scope:
The Trust Bureau implements multiple security layers:
| Layer | Mechanism |
|---|---|
| Identity Binding | Biometric verification anchors every credential to a real human (Fixed Binding) |
| Consent Gates | No credential data flows without explicit, auditable holder consent (GP-18) |
| Cryptographic Credentials | SD-JWT Verifiable Credentials with ES256 signatures |
| Audit Trail | Immutable, append-only evidence log for all operations |
| Key Management | Per-issuer ES256 key pairs, DID-based identity, key rotation support |
| Rate Limiting | Per-key and per-IP rate limits on all API endpoints |
| Webhook Integrity | HMAC-SHA256 signatures on all webhook deliveries |
| Token Decay | Credentials expire automatically — no permanent standing trust |
Security reports: security@trua.cloud
General inquiries: bureau@trua.cloud
This policy is also available in machine-readable format at
/.well-known/security.txt
per RFC 9116.