# Trusta Security Overview

Trusta is designed around deterministic, auditable trust evaluation. Published
trust claims are intended to trace back to explicit evidence and evaluation
state.

The platform separates runtime concerns across the dashboard, API, workers,
shared packages, and CDK-managed infrastructure. Sensitive artifacts are stored
outside the database, and public trust pages are rendered from published
public-safe contracts.

## Reporting a vulnerability

Report suspected vulnerabilities to <security@trusta.dev>. The machine-readable
policy is published at
[/.well-known/security.txt](https://trusta.dev/.well-known/security.txt). Please
give us a reasonable window to fix an issue before disclosing it publicly.

## Related

- [Privacy policy](https://trusta.dev/privacy)
- [Terms of service](https://trusta.dev/terms)
- [Contact](https://trusta.dev/contact)
- [Homepage trust preview](https://trusta.dev/#trust-preview)
