Security is core to what ARGOS is. If you believe you’ve found a vulnerability, we want to hear from you — and we’ll work with you in good faith to fix it.
How to report
Email connect@remitso.com with the subject line “Security — vulnerability report”. Please include:
- a description of the issue and its potential impact;
- clear steps to reproduce it (proof-of-concept where possible);
- the affected URL, component, or version; and
- how you’d like to be credited, if at all.
Our commitment to you
- We’ll acknowledge your report within 3 business days.
- We’ll investigate, keep you updated on progress, and let you know when it’s fixed.
- We won’t pursue or support legal action against researchers who follow this policy in good faith.
- With your permission, we’re glad to credit you once the issue is resolved.
Please do
- Give us a reasonable time to fix an issue before disclosing it publicly.
- Only test against your own account/tenant, and only to the extent needed to demonstrate the issue.
- Stop and report immediately if you access another tenant’s data — do not view, store, or share it.
Please do not
- Run denial-of-service tests, spam, or high-volume automated scanning against the service.
- Use social engineering, phishing, or physical attacks against our staff or infrastructure.
- Access, modify, or destroy data that isn’t yours, or degrade the service for other customers.
Scope
This policy covers this website (www.truoco.com) and the ARGOS application at argos.truoco.com. Issues in third-party services we rely on (see Sub-processors) should be reported to those providers, though we’re happy to help coordinate.
A machine-readable version of these contacts is published at /.well-known/security.txt.