txshield Security
Home/Security posture.

Security posture.

Where we are on encryption, key handling and compliance. Plus how to report a vulnerability.

TLS 1.2+ everywhereLast updated 2026‑09‑26

Responsible disclosure

Found something? Tell us first. We respond within 48 hours.

Email
security@txshield.dev
security.txt
/.well-known/security.txt
Severity
Mark [CRITICAL] in subject for anything that exposes customer data, lets a third party act as a customer, or breaks the simulate→verdict integrity.
Bounty
Negotiated case-by-case. We don't run a points-based program, but we pay for real findings.

Please do not use customer data, run automated scanners against production, or test on accounts that aren't yours. Use a free-tier sandbox key for everything.

What we do today

Encryption

API keys hashed with HMAC-SHA256 at rest. All traffic TLS 1.2+ (TLS 1.3 preferred). Webhook payloads signed HMAC-SHA256 with per-endpoint secret.

Key rotation

You rotate API keys from the dashboard at any time.

Isolation

API keys, risk policies and audit records are scoped to the owning account. Program and token blacklists are platform-wide.

Logs & audit

On the institutional tier each simulation writes a signed, append-only audit record. sim_id is the stable join key — quote it on any support request.

Compliance

For a security questionnaire, architecture diagram or sub-processor list, email security@txshield.dev from a corporate domain.

Sub-processors