Skip to main content
Register for FutureLink Barcelona 2026 Today→
TraceLink — Network for Greater Good
AI Mode Agents AI Solutions Network Resources About
LOG IN TraceLink Classic OPUS Platform
Vulnerability Disclosure Policy

Breadcrumb

  1. Home

Vulnerability Disclosure Policy

banner-image

At TraceLink, we recognize the mission-critical nature of our software and our responsibility as custodians of our customers' information. We are fully committed to the security of our products and the protection of the data entrusted to us. By ensuring robust security measures, we help safeguard the integrity of the supply chain, ultimately supporting the delivery of the highest quality care to the patients our customers serve.

Authorization (Safe Harbor)

Good faith efforts to comply with this policy during research will be considered authorized research. Our commitment to the researcher is to understand the issues being reported and work to resolve the issue in a timely manner. Authorized research will not result in pursuing legal action, provided such authorized testing complies with the guidelines set forth herein.

Guidelines (Scope)

Research activities are required to:

  • Notify TraceLink as soon as possible after discovering a real or potential security issue, or after discovering exposure of non-public data.
  • Be actively seeking to avoid privacy violations, degradation of user experience, disruption of systems, and destruction or manipulation of non-test data.
  • Be genuine security research and not findings directly originating from automated scanning tools.
  • Be targeted against Validation or iTest environments where applicable. No Production environment should be used as the target for research activities (Please see scope below for associated URLs).
  • Be obtainable through public means. No additional access will be provided to any individual for research activities beyond what such individual is able to access by self-enrolling.

Scope

ApplicationURLs
OPUS Platform and Applications

OPUS.tracelink.com

(API) val-opus.tracelink.com

Track & Trace Services

itest.tracelink.com

itest.eu1.tracelink.com

(API) itestapi.tracelink.com

(API) itestapi.eu1.tracelink.com

TraceLink Product SSOsso.tracelink.com
Corporate Websitewww.tracelink.com

Out-of-Scope Vulnerabilities:

  • Username / Email Enumeration
  • Concurrent User Sessions
  • Email Spoofing / SPF, DKIM or DMARC configuration
  • Social Engineering
  • Brute Force Attacks
  • Denial of Service Attacks
  • Missing cookie flags
  • Missing security headers
  • CORS misconfiguration against functionality without security impact
  • Cross-site Request Forgery against non-sensitive functionality
  • Presence of autocomplete attribute on web forms
  • Reverse Tabnabbing
  • Clickjacking without proven impact/unrealistic user interaction
  • HTTP Request smuggling without security impact
  • Banner grabbing/Version disclosure
  • Verbose messages/files/directory listings without disclosing any sensitive information
  • Third-party library vulnerabilities with no impact to TraceLink applications
  • Automated Scanner Reports
  • GrahpQL Introspection
  • Weak Cipher without Exploitability

Reporting (Process)

Send an email to security-alerts [at] tracelink.com (security-alerts[at]tracelink[dot]com)

Reports containing sensitive information or non-public data exposure must be encrypted using the below GPG public key. Critical or high severity reports may also be encrypted using the following key.

https://www.tracelink.com/pgp-key.txt

Report Structure

Reports need to contain a detailed understanding of the vulnerability for TraceLink to properly validate. This should include the following information at a minimum:

  • Description of Vulnerability
  • Steps to Reproduce the Finding
  • OWASP Risk Rating or CVSS (v3.1 or higher) Score and Metric Values

If steps to reproduce are not accurate or produce a different result than the description, additional details may be required. Arbitrary severity rating without one of the two mentioned risk rating methodologies will be treated as an Informational severity issue.

Disclosure

Disclosure of issues related to security research against TraceLink products must be in coordination with the TraceLink teams. This process will be handled in-line, with the reporting of the vulnerability, and following the confirmation of an issues remediation, a researcher may request the approval to publicly disclose the vulnerability, however the researcher must provide a copy to TraceLink for approval prior to any such release.

Acknowledgement

Acknowledgement may be provided to the security researcher in the form of a Letter of Gratitude for high and critical severity issues as determined by TraceLink. TraceLink Security will maintain internal tracking to provide validation in the event of seeking to utilize this letter for validation of security research expertise and experience.
TraceLink does not currently offer monetary awards or bounties for vulnerabilities.

Questions

Any questions or clarification needed with respect to this policy must be directed to security-alerts [at] tracelink.com (security-alerts[at]tracelink[dot]com). The lack of clarity around any directive mentioned in this policy must be addressed prior to any research activities.

Cookie Settings

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies or similar tracking technologies. Please see below for an overview of the categories of cookies and similar technologies used on this site. You can allow or deny some of all of them, except Strictly Necessary Cookies which are required to provide the site to you. However, blocking some types of cookies may impact your experience of the site and services we are able to offer.

Please see our Cookie Policy for more details, including a list of the cookies we use. You can change your consent options at any time by following the “Cookie Settings” link in the Cookie Policy.
'Strictly Necessary' cookies let you move around the Site and use essential features like secure areas, shopping baskets and online billing. Without these cookies you would not be able to navigate between pages or use certain vital features of our Site, so we do not require your consent for their use. These cookies don't gather any information about you that could be used for marketing or remembering where you've been on the internet. For example, we use these Strictly Necessary cookies to identify you as being logged in to the Site. You can set your browser to block or alert you about these cookies, but if you do so, some parts of the Site will not work.
'Performance' cookies collect information about how you use the Site, such as which pages you visit, the time spent on the Site and if you experience any errors. We use performance cookies to provide aggregated statistics on how the Site is used and help us improve the Site including by measuring any errors that occur.
'Functional' cookies are used to provide services or to remember settings to improve your visit. We use 'Functionality' cookies to remember your settings and choices and show you when you're logged in to the Site.
‘Targeting' cookies are linked to services provided by third parties, such as 'Like' buttons and 'Share' buttons. The third party provides these services in return for recognizing that you have visited the Site. We also use 'Targeting' cookies to gather information that could be used to display content that we think may interest you.
Register for FutureLink Barcelona 2026 Today→
TraceLink — Network for Greater Good
Log In OPUS Platform · TraceLink Classic
AI Mode
Featured Report The Agentic Supply Chain Operating Model →

Agentic Business Processes

External Manufacturing Logistics Transportation Commerce Compliance

Products

Digital Transaction Exchange Process Collaboration Global Track-and-Trace Regulatory Compliance Real-Time Intelligence

Resources

Resource Center TraceLink University Partners Community Customers Events

About TraceLink

Company Overview Newsroom Culture & Careers Open Jobs Legal & Trust Center Corporate Social Responsibility Network Directory Glossary

Hot Topics

Eliminate Stockouts Improve OTIF Reduce Costs Increase End-to-End Visibility Accelerate Order-to-Cash Optimize Inventory Levels Scale Cross-Partner Execution
Need assistance? Contact Technical Support→

Contact Us Today

Transform your supply chain operations with a human-agent workforce.

Contact Us →

Stay Up-to-Date

Subscribe to receive industry insights and evolving trends.

Thanks — you're subscribed.

© TraceLink Inc. 2009–2026 All Rights Reserved