Translations are provided for convenience. If a translated version differs from the English version, the English version controls.
Security approach
Troodo is designed to minimize credential movement and isolate each organization's workspace. Security controls are reviewed as the service evolves, but this page does not claim a certification, audit report, penetration-test result, or bug-bounty program that has not been completed.
Current controls
The production architecture currently includes the following technical and operational safeguards:
- Tenant-scoped database row-level security plus owner, admin, manager, member, and viewer permissions.
- Service-role, AI, billing, and GitHub App credentials remain server-only and are not exposed through public environment variables.
- GitHub, GitLab, and Stripe webhook signatures are verified before trusted processing, with bounded background work and rate limits.
- Browser-direct GitLab and GitHub Enterprise tokens stay in the user's browser; manual provider credentials are not persisted.
- Transport security headers, Sentry error monitoring, safe diagnostics, and audit events support detection and investigation.
Report a vulnerability or incident
Email vitor@madai.com.br with a concise subject that begins with ‘Troodo security’. Use a secure private channel for evidence and do not attach live credentials, unnecessary customer data, or exploit data from another tenant.
Useful report content
Include the affected route or component, time and time zone, impact, safe reproduction steps, and a way to reply. Use test accounts and redact tokens, source code, personal data, and customer content. We may ask for an encrypted or otherwise safer evidence-transfer route.
Responsible testing
Test only accounts, workspaces, and data you are authorized to use. Do not access another tenant, degrade availability, automate high-volume requests, use social engineering, send malware, or retain discovered data. Troodo has no public safe-harbor or paid bounty commitment unless confirmed in writing before testing.
How reports are handled
Troodo will make a reasonable effort to acknowledge, triage, contain, remediate, and communicate a verified issue. Timing depends on severity and available evidence. Affected customers will be notified when appropriate and as required by applicable law or a signed agreement; no public response-time promise is made on this page.
Operational scope
This page covers the Troodo hosted application and its production integrations. Provider platforms, customer-managed GitLab or GitHub Enterprise instances, customer networks, and third-party browser extensions remain outside Troodo's direct control and should be reported to their operator as well.
Data handling and privacy
Security reports are used to investigate and prevent harm and are shared only with people and service providers who need them, or when law requires it. See the Privacy Notice for the broader description of Troodo's data handling.