Device-trust design
TrustFlare uses cryptographic proofs and customer-defined device policies to support access decisions. Signed device information, expiring challenges and confirmation steps are designed to reduce impersonation and replay. A valid signature does not by itself prove that every device-reported fact is correct.
Local user verification is performed by the device platform. Supported checks and key protection differ between platforms and hardware. Confirm the required behavior for the release you deploy.
Website and form protection
The public site is served through Cloudflare over HTTPS. Website forms use signed, expiring request tokens, input validation, honeypot checks and rate limits. Browser security headers constrain content loading and framing.
Form data are stored in Cloudflare D1 and notifications are delivered through Telegram as described in Privacy. Do not include credentials or unrelated personal information in reports.
Deployment responsibilities
In customer-hosted deployments, the customer controls the core, storage, administrators, backups and network exposure. Hosted services require agreement on infrastructure, support access, retention and incident contacts. Neither deployment model is a substitute for customer access governance.
Development and release checks
The development workflow includes specifications, automated checks and review of authentication and secrets changes. Security and signing capabilities must be assessed against the particular release and operating system; do not assume a planned certification or signing feature is already available.
Ask for the available distribution paths and relevant release and security evidence before a production rollout.
Report a vulnerability
Use the security report form or email security@trustflare.tech. Include the affected URL or version, reproducible steps and the likely impact. Anonymous reports are accepted; provide an email if you want a reply.
Test only systems and accounts you are authorized to test. Do not access other users’ data, disrupt availability or perform social engineering. If you encounter unrelated personal data, stop and report the minimum information needed. Ask us to arrange a suitable channel before sharing sensitive evidence.
Incidents involving personal data
Incident handling includes assessment, containment, remediation and appropriate notification. If we process customer data, we notify the controller without undue delay as required by the applicable processing terms and law.
Where GDPR applies to us as controller, a reportable breach must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours of awareness; individuals must be informed without undue delay when the breach is likely to pose a high risk, subject to the legal exceptions. These duties differ from routine vulnerability-report acknowledgements.
Customer security reviews
Contact legal@trustflare.tech for questionnaires and available supporting evidence. We identify which controls apply to your deployment and which requirements still need agreement.
Release verification references
For the referenced 0.6.0 release, the published verification paths are listed below. Access may be restricted; ask for the files matching your release if a download is unavailable. Obtain the signing key through a trusted channel before using minisign to verify a manifest.