Security and vulnerability disclosure

Draft — to be reviewed by counsel

This is a working draft prepared for review by qualified counsel. It is not legal advice and is not yet binding. Items in [SQUARE BRACKETS] are placeholders to be completed by REAT Global; notes marked “Counsel:” are decisions for review. See the placeholder register.

Version 1.0-draftLast updated [LAST UPDATED DATE]Effective [EFFECTIVE DATE]Draft prepared 30 September 2026

On this page

This page summarises how the Tractrix products protect your data and explains how to report a security vulnerability to us. The detailed, contractual list of measures is Annex II of the Data Processing Addendum.

1. Security overview

Design principles

  • Local first. Tractrix for QGIS, the OpenAirside engine and the CAD add-ins with the local engine run entirely on your computer and contain no telemetry. Sensitive projects never need to leave your network.
  • Open source. The engine and the desktop products are published under GPL-2.0-or-later, so their behaviour can be independently reviewed.
  • No stored secrets. Tractrix Cloud stores passwords, API tokens, sessions and e-mail links only as one-way hashes.
  • Tenant isolation by construction. Every record belongs to one organisation, and every request passes through one authorisation layer.

Tractrix Cloud

  • Accounts: Argon2id password hashing; e-mail verification; rate-limited sign-in, sign-up, verification and reset; responses that do not reveal whether an address is registered. Multi-factor authentication and single sign-on are planned.
  • Sessions: 15-minute access tokens held only in memory; refresh tokens rotated on every use with reuse detection; HttpOnly, SameSite=Strict, Secure cookies; all sessions invalidated on password change.
  • Roles: viewer, member, admin and owner, with the least privilege needed; non-members cannot even detect that an organisation exists.
  • API tokens: scoped to one user and one organisation, shown once, optional expiry, revocable, with last-use tracking; they cannot manage accounts, members or other tokens.
  • Web application: strict Content Security Policy without inline scripts, anti-framing, no-sniff and referrer policies, HSTS, no caching of API responses; downloadable HTML reports are isolated.
  • Input limits: size, complexity and time limits on uploads and simulations protect the service from abuse.
  • Audit log: security-relevant events recorded without secrets and with truncated IP addresses, visible to your organisation's admins.
  • Hosting: [HOSTING REGION]; encryption in transit (TLS 1.2+) and at rest, encrypted backups retained for [BACKUP RETENTION PERIOD] — to be confirmed with the production hosting provider.

Desktop products

  • No network access in the QGIS plugin or the local engine. The CAD add-ins contact Tractrix Cloud only when you choose the cloud engine and consent to cloud processing.
  • The CAD add-ins store a Cloud API token encrypted with Windows DPAPI for your Windows user, and connect over HTTPS.
  • Release files are published with SHA-256 checksums on the download page so you can verify them. [CODE SIGNING STATUS]

Certifications and questionnaires

REAT Global does not currently hold a security certification of its own: [SECURITY CERTIFICATIONS]. Our hosting providers' certifications will be listed on the sub-processors page. Customers, including airports subject to the NIS2 Directive or national critical-infrastructure rules, can request our security questionnaire answers at [SECURITY CONTACT EMAIL].

Your part

  • Use a unique password, remove members who leave, and grant the lowest role that works.
  • Give API tokens an expiry date and revoke them when no longer needed.
  • Review your organisation's audit log.
  • Decide whether a project's data is appropriate for the cloud; if not, use the local engine.

Incident notification

If a security incident affects your data, we will tell you without undue delay, aiming for 48 hours for customer personal data as set out in the DPA, and will notify authorities and individuals where the law requires.

2. Vulnerability disclosure policy

We welcome reports from security researchers and users. If you believe you have found a vulnerability in a Tractrix product, please tell us privately so that we can fix it before it is disclosed.

Scope

In scope:

  • Tractrix Cloud at [CLOUD SERVICE URL], its web application and API;
  • the tractrix.io website;
  • Tractrix for AutoCAD, Tractrix for Revit, Tractrix for QGIS, the OpenAirside engine and the tractrix-engine binary, and the source code in the Downloads (account required).

Out of scope:

  • denial-of-service or volumetric testing, spam, and social engineering or phishing of our staff or users;
  • physical attacks, and attacks on the offices or data centres of REAT Global or its providers;
  • third-party services such as GitHub, our hosting, e-mail or payment providers (report to them directly), and Autodesk or QGIS host applications;
  • reports without a demonstrated security impact, such as missing headers on static pages, clickjacking of pages without state-changing actions, self-XSS, software version disclosure, or best-practice recommendations for e-mail authentication records;
  • results of automated scanners without verification;
  • vulnerabilities in third-party products (such as Python packages) unless our use of them introduces the flaw — please report those to their maintainers;
  • accuracy of engineering results (please report those as ordinary bugs on GitHub).

How to report

  • Use GitHub private vulnerability reporting on the repository (Downloads (account required)), or e-mail [SECURITY CONTACT EMAIL]. To encrypt sensitive details, ask for our key in a first message without details. Please do not open a public issue, discussion or pull request.
  • Include the affected product and version or URL, a description of the vulnerability and its impact, step-by-step reproduction instructions or a proof of concept, and how you would like to be credited.
  • Our machine-readable contact details are in /.well-known/security.txt (RFC 9116).

Rules of engagement

  • Test only against accounts and organisations you created, or with the explicit permission of their owner. Use a local installation (the platform runs locally from the repository) wherever possible.
  • Do not access, modify or delete data that is not yours. If you encounter other people's data or customer content, stop, do not keep or share it, and tell us immediately.
  • Do not degrade the service: keep automated testing to a low rate, and do not run tests that could exhaust resources.
  • Do not use a vulnerability beyond what is necessary to demonstrate it (no pivoting, persistence or data exfiltration).
  • Give us reasonable time to fix the issue before any disclosure, and do not disclose customer data at any time.

Safe harbour

If you act in good faith and follow this policy, we will consider your research to be authorised; we will not bring or support legal action against you for it, including under computer-misuse laws (such as the UK Computer Misuse Act 1990 or the US Computer Fraud and Abuse Act) or anti-circumvention laws, and we waive the restrictions in our Acceptable Use Policy and Cloud Terms that would otherwise prohibit it, to the extent needed for that research. If a third party brings legal action against you for research that complied with this policy, we will make it known that your actions were authorised by us. This safe harbour does not authorise testing of third parties' systems and cannot bind public authorities. If in doubt, ask us first at [SECURITY CONTACT EMAIL].

Supported versions

Security fixes are provided for the running Tractrix Cloud service and the website; the latest 1.x release of Tractrix for AutoCAD and Revit; the latest release of Tractrix for QGIS on plugins.qgis.org; and the latest release of the OpenAirside engine and the version bundled with the latest CAD release. Please upgrade older releases. The repository's SECURITY.md file carries the same policy.

What you can expect

Table 1 Response timelines (targets).
StepTarget
Acknowledge your report3 business days
Initial assessment and severity (CVSS v4.0)10 business days
Fix or mitigation — critical and high severityWithin 30 days of confirmation (critical issues in the hosted service as fast as possible)
Fix — medium and low severityIn the next scheduled release, normally within 90 days
Coordinated public disclosureWhen a fix is available, or 90 days after the report, whichever is earlier, unless agreed otherwise

We will keep you informed of progress, publish a security advisory (with a CVE identifier where appropriate) for vulnerabilities in the released software, and credit you in the advisory unless you prefer to remain anonymous. We do not currently run a paid bug bounty programme.

Where a vulnerability requires it, we will also meet reporting obligations that apply to us as a manufacturer of software products, including those of the EU Cyber Resilience Act as they come into application. [Counsel: confirm whether the open-source steward or manufacturer provisions of Regulation (EU) 2024/2847 apply to the Tractrix products, and the reporting timelines from 11 September 2026.]