Incident response
Last updated: August 2026
What happens if we suspect a breach. This is a founder-operated procedure, not a 24/7 security operations centre, and it does not promise a fixed notification clock.
TryTokka is a solo-operated product. There is no paid bug bounty and no claim of around-the-clock coverage. The compensating facts are a published procedure, a dedicated inbox, and an incident history that stays dated even when it is empty.
Report a vulnerability or suspected incident: security@trytokka.com. Do not include live credentials in the first email. security.txt and the safe-harbour terms on /security apply.
- 1
Report and detect
Anyone can report a suspected incident or vulnerability to security@trytokka.com. Founder-operated monitoring of errors, status checks, and unusual key-access patterns is how we notice issues we did not get emailed about.
- 2
Contain
Affected paths are disabled or rotated first: ENCRYPTION_KEY (with the dual-key window), CRON_SECRET, and any leaked env value. Production stays up only if it can stay contained.
- 3
Assess
We determine whether stored credential ciphertext, emails, or payment identifiers were in the blast radius, and whether ENCRYPTION_KEY was exposed with the database. That pairing is the realistic worst case in the threat model.
- 4
Notify
Regulators and users are notified where applicable law requires it. Timing and recipients depend on the incident, jurisdiction, and assessed risk. A user notice would state known impact and tell you to revoke the dedicated TryTokka key at each provider.
- 5
Publish
A dated entry is added to the incident history on /security. Until then, that section stays dated as last-reviewed so silence is not mistaken for an unmaintained page.
What you should do if we contact you
Revoke the dedicated TryTokka billing or usage key at each provider. Because that key cannot run completions, revoking it stops our access without taking down your product traffic. Then create a new dedicated key if you still want Scout to sync.
Incident history (including the last-reviewed date when the list is empty) is on the Security page.