GGPSS ONETrust & security
Coordinated vulnerability disclosure
We welcome reports from security researchers. Acting in good faith under this policy is authorised and will not lead to legal action (safe harbor).
- Report to mailto:[email protected] or through the form below.
- We acknowledge every report within 72 hours and keep you informed.
- Target remediation: 90 days for confirmed issues; critical issues faster.
- Please avoid data exfiltration, service disruption and access to other customers’ data; test only against accounts you own.
- We credit reporters in advisories unless they prefer otherwise.
Software bill of materials (SBOM)
CycloneDX 1.5
Versiondev
Generated2026-10-11 13:32 UTC
Components318
SHA-256a0e9e19bd5885613d2104324ced7adfedfc4bc8d9ecf08671daac3132a5ba094
Signatureunsigned
Platform vulnerability status
Open items in our own dependencies, by severity. Details are published as advisories once fixed.
Critical0
High32
Medium0
Low0
Cyber Resilience Act: vulnerability reporting obligations active since 11.09.2026; essential requirements apply from 11.12.2027.