EvidenceTrail Trust file

EvidenceTrail security contact

Security contact and incident intake status for early UK social-landlord pilot review.

Phase 2 update

Phase 2 announced for Oct 2026: see what changes.

Current status

This page records dev-mode security intake metadata when the application has a store configured. It remains a pilot placeholder only: it is not a production monitored security contact, not a vulnerability disclosure programme, not a breach-notification SLA, and not legal advice.

The related draft is docs/security-contact-intake-draft.md. Security incident workflow notes are in docs/security-incident-response-draft.md.

Incident intake metadata

The production incident intake metadata process should capture enough detail for triage while avoiding unnecessary personal data sharing.

Dev-mode metadata intake

Do not include tenant names, proof-link tokens, passwords, API keys, secrets, or live exploit material. The dev-mode endpoint records metadata only and does not store the raw report text.

Production requirements

Official references