TRUST / WEBSITE SECURITY

Security, stated plainly.

Current controls for this pre-release site, separated from the proposed evidence platform.

Current website controls

Contact submissions are validated on the server and stored in a D1 database. The public endpoint accepts submissions but does not expose a read or listing function. It uses an origin check, payload-size limits, a hidden anti-spam field, and hourly request limiting.

Submission text is not intentionally logged by the application. Query parameters use bound statements. No secrets or customer artifacts are requested through the site.

What is not deployed

Production agent ingestion, scoped runtime credentials, customer workspaces, artifact sealing, confidential capture, and independent certification are not enabled. Their appearance in product concepts does not mean the associated security controls are implemented.

UpTrain does not claim SOC 2, ISO 27001, an external audit, an uptime guarantee, or independent verification of this website’s security.

Report a concern

Choose Security report on the contact form. Include the affected route, a concise description, and steps that demonstrate the issue without exposing sensitive data. Do not include passwords, access tokens, or another person’s information.

There is no published bounty or guaranteed response time. Report only issues within systems you are authorized to examine. Avoid disruption, social engineering, bulk data access, or testing third-party infrastructure.

Before connecting a real runtime

Any future pilot must agree authorization, data minimization, access controls, secret handling, export permissions, retention, and incident contact arrangements. A verified artifact does not replace those safeguards.

Submit a privacy question or request →