Skip to main content
Home
  • AI Mode
  • Supply Chain Orchestration
    fast
    Supply Chain Orchestration
    • Life Sciences Company
    • Direct Material Supplier
    • Contract Manufacturer
    • Third Party Logistics
    • Wholesale Distributor
    • Healthcare Provider
    • Retail Pharmacy
  • Network
  • Products
    fast
    Products
    • Multienterprise Information Network Tower (MINT)
    • Process Orchestration for Empowered Teams (POET)
    • Track-and-Trace
  • Resources
    fast
    Resources
    • Resource Center
    • TraceLink University
    • Partners
    • Community
    • Events
  • About
    fast
    About
    • Our Story
    • Newsroom
    • Culture and Careers
    • Leadership
    • Our Values
    • Corporate Social Responsibility
    • Contact Sales
  • Log In
    • Tracelink Classic
      TraceLink Classic app.tracelink.com
      Redirect
    • Opus Platform
      Opus Platform opus.tracelink.com
      Redirect
Log In
  • Tracelink Classic
    TraceLink Classic app.tracelink.com
    Redirect
  • Opus Platform
    Opus Platform opus.tracelink.com
    Redirect
Vulnerability Disclosure Policy

Breadcrumb

  1. Home

Vulnerability Disclosure Policy

banner-image

At TraceLink, we recognize the mission-critical nature of our software and our responsibility as custodians of our customers' information. We are fully committed to the security of our products and the protection of the data entrusted to us. By ensuring robust security measures, we help safeguard the integrity of the supply chain, ultimately supporting the delivery of the highest quality care to the patients our customers serve.

Authorization (Safe Harbor)

Good faith efforts to comply with this policy during research will be considered authorized research. Our commitment to the researcher is to understand the issues being reported and work to resolve the issue in a timely manner. Authorized research will not result in pursuing legal action, provided such authorized testing complies with the guidelines set forth herein.

Guidelines (Scope)

Research activities are required to:

  • Notify TraceLink as soon as possible after discovering a real or potential security issue, or after discovering exposure of non-public data.
  • Be actively seeking to avoid privacy violations, degradation of user experience, disruption of systems, and destruction or manipulation of non-test data.
  • Be genuine security research and not findings directly originating from automated scanning tools.
  • Be targeted against Validation or iTest environments where applicable. No Production environment should be used as the target for research activities (Please see scope below for associated URLs).
  • Be obtainable through public means. No additional access will be provided to any individual for research activities beyond what such individual is able to access by self-enrolling.

Scope

ApplicationURLs
OPUS Platform and Applications

OPUS.tracelink.com

(API) val-opus.tracelink.com

Track & Trace Services

itest.tracelink.com

itest.eu1.tracelink.com

(API) itestapi.tracelink.com

(API) itestapi.eu1.tracelink.com

TraceLink Product SSOsso.tracelink.com
Corporate Websitewww.tracelink.com

Out-of-Scope Vulnerabilities:

  • Username / Email Enumeration
  • Concurrent User Sessions
  • Email Spoofing / SPF, DKIM or DMARC configuration
  • Social Engineering
  • Brute Force Attacks
  • Denial of Service Attacks
  • Missing cookie flags
  • Missing security headers
  • CORS misconfiguration against functionality without security impact
  • Cross-site Request Forgery against non-sensitive functionality
  • Presence of autocomplete attribute on web forms
  • Reverse Tabnabbing
  • Clickjacking without proven impact/unrealistic user interaction
  • HTTP Request smuggling without security impact
  • Banner grabbing/Version disclosure
  • Verbose messages/files/directory listings without disclosing any sensitive information
  • Third-party library vulnerabilities with no impact to TraceLink applications
  • Automated Scanner Reports
  • GrahpQL Introspection
  • Weak Cipher without Exploitability

Reporting (Process)

Send an email to security-alerts [at] tracelink.com (security-alerts[at]tracelink[dot]com)

Reports containing sensitive information or non-public data exposure must be encrypted using the below GPG public key. Critical or high severity reports may also be encrypted using the following key.

https://www.tracelink.com/pgp-key.txt

Report Structure

Reports need to contain a detailed understanding of the vulnerability for TraceLink to properly validate. This should include the following information at a minimum:

  • Description of Vulnerability
  • Steps to Reproduce the Finding
  • OWASP Risk Rating or CVSS (v3.1 or higher) Score and Metric Values

If steps to reproduce are not accurate or produce a different result than the description, additional details may be required. Arbitrary severity rating without one of the two mentioned risk rating methodologies will be treated as an Informational severity issue.

Disclosure

Disclosure of issues related to security research against TraceLink products must be in coordination with the TraceLink teams. This process will be handled in-line, with the reporting of the vulnerability, and following the confirmation of an issues remediation, a researcher may request the approval to publicly disclose the vulnerability, however the researcher must provide a copy to TraceLink for approval prior to any such release.

Acknowledgement

Acknowledgement may be provided to the security researcher in the form of a Letter of Gratitude for high and critical severity issues as determined by TraceLink. TraceLink Security will maintain internal tracking to provide validation in the event of seeking to utilize this letter for validation of security research expertise and experience.
TraceLink does not currently offer monetary awards or bounties for vulnerabilities.

Questions

Any questions or clarification needed with respect to this policy must be directed to security-alerts [at] tracelink.com (security-alerts[at]tracelink[dot]com). The lack of clarity around any directive mentioned in this policy must be addressed prior to any research activities.

Cookie Settings

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies or similar tracking technologies. Please see below for an overview of the categories of cookies and similar technologies used on this site. You can allow or deny some of all of them, except Strictly Necessary Cookies which are required to provide the site to you. However, blocking some types of cookies may impact your experience of the site and services we are able to offer.

Please see our Cookie Policy for more details, including a list of the cookies we use. You can change your consent options at any time by following the “Cookie Settings” link in the Cookie Policy.
'Strictly Necessary' cookies let you move around the Site and use essential features like secure areas, shopping baskets and online billing. Without these cookies you would not be able to navigate between pages or use certain vital features of our Site, so we do not require your consent for their use. These cookies don't gather any information about you that could be used for marketing or remembering where you've been on the internet. For example, we use these Strictly Necessary cookies to identify you as being logged in to the Site. You can set your browser to block or alert you about these cookies, but if you do so, some parts of the Site will not work.
'Performance' cookies collect information about how you use the Site, such as which pages you visit, the time spent on the Site and if you experience any errors. We use performance cookies to provide aggregated statistics on how the Site is used and help us improve the Site including by measuring any errors that occur.
'Functional' cookies are used to provide services or to remember settings to improve your visit. We use 'Functionality' cookies to remember your settings and choices and show you when you're logged in to the Site.
‘Targeting' cookies are linked to services provided by third parties, such as 'Like' buttons and 'Share' buttons. The third party provides these services in return for recognizing that you have visited the Site. We also use 'Targeting' cookies to gather information that could be used to display content that we think may interest you.

Footer

  • Quick Links
    Get a Demo
    TraceLink Network Directory
    The Network
    OPUS Platform
    Technical Support
    Open Jobs
    API: Terms of Use
  • Products
    Multienterprise Information Network Tower
    U.S. DSCSA Compliance
    Targeted Recalls
    Process Orchestration for Empowered Teams
    Serialization
    Global Compliance
  • Resources
    Resource Center
    Events
    TraceLink University
    Partners
    Community
  • About TraceLink
    Our Story
    Newsroom
    Culture & Careers
    Leadership
    Our Values
    Corporate Social Responsibility
  • Hot Topics
    Transaction Integration
    Supply Chain Visibility
    DSCSA Compliance
    Process Orchestration
    Kazakhstan Compliance for Pharmaceuticals
    Kyrgyzstan Compliance for Pharmaceuticals
Follow Us on Social
Facebook
Linkedin
X
Legal & Trust.
© TraceLink Inc. 2009-2026 All Rights Reserved
Contact Us Today
Contact us today to begin your journey toward agentic supply chain orchestration — digitalize your end-to-end supply chain with intelligence, flexibility, and collaborative orchestration.
Contact Us
Stay Up-to-Date
Subscribe to receive industry insights and stay at the forefront of evolving trends.
Subscribe