Sample deskNorthbay Forums (Sample)

48-hour windowEnforceable since 19 May 2026

TrustDesk · document

Security

What TrustDesk stores, who else processes it, and how to report a vulnerability.

Reporting a vulnerability

Email hello@thecompound.tech. Include the URL, what you did, and what you saw. There is no bounty and no NDA to sign. We will confirm receipt, and we will tell you what we changed.

The same address, with a machine-readable expiry, is published at /.well-known/security.txt under RFC 9116.

Accounts

TrustDesk has no user accounts. There is nothing to sign in to, no password to reset and no session to steal, and a build gate fails the deploy if an authentication route ever appears in this repository while this page still says otherwise.

What is stored

  • A report submitted through the desk: what the reporter tells us, when they told us, and every action taken on it afterwards — this is the evidence log, it is append-only by design, and it is the product
  • The reporter's own status link is a long random token in a URL. It is not a login, it cannot be guessed, and anyone holding it can see that one report
  • If you use the free policy generator, the platform name, site URL and contact address you type are used to write the policy text
  • If you use the contact form, your name, email, platform URL and message
  • Anonymous usage analytics — page views and clicks. Form inputs are masked in session recordings and no profile is created for a visitor who never identifies themselves

Who else processes data

  • Stripe — takes the payment and holds the card details — we never see a card number
  • Supabase — the database holding the append-only evidence log and the contact rows
  • PostHog — anonymous product analytics, proxied through this domain
  • Vercel — serves this site and holds its access logs

Also true

  • The evidence log is append-only. An entry cannot be edited or deleted after it is written, including by us — that is what makes it evidence rather than a record of what somebody remembers.
  • No image is ever uploaded to this site. A report describes where the material is; it does not carry it.
  • The free policy generator stores nothing. It takes three fields, returns text, and keeps neither.

TrustDesk is built and run by Compound Labs. The declarations on this page are part of this product's own configuration and are re-checked at every deploy against the repository they describe: a product that claims to have no accounts and ships an authentication route fails the build, and so does one that takes payment without naming its payment processor here.