Support and Contact Channels
How to get help from Truestamp - email [email protected] for general help and [email protected] for responsible vulnerability disclosure, the public /support page (feedback, roadmap, changelog), the knowledge base at /knowledge with a page per concept, and /.well-known/security.txt.
Overview
Truestamp keeps its support and contact channels small and public. General help goes
to [email protected], and security vulnerabilities go to [email protected]
under a responsible disclosure program that is also published in machine-readable
form at /.well-known/security.txt. The public support page at
www.truestamp.com/support gathers everything in
one place: the email channels, embedded feedback, roadmap, and changelog panels, a
door into the knowledge base, and links to self-serve resources such as the API
documentation and the home-page FAQ. The knowledge base itself is a section of the site
in its own right, at www.truestamp.com/knowledge.
None of these pages require an account or sign-in.
How do I contact Truestamp support?
Email [email protected]. The support page states that the team responds within 24 hours. The same address is listed on the support page at www.truestamp.com/support, which is public and needs no sign-in. For background on the product itself before writing in, start with what Truestamp is.
Where do I send feedback, or follow the roadmap and changelog?
The support page hosts three embedded panels, each opening in a popup on the page itself so no separate account is needed:
- Feedback: suggest features, vote on ideas, and report issues. The page notes that every post is read by the team.
- Roadmap: see what is being worked on now, what is planned next, and what is under consideration.
- Changelog: recent releases and product updates, with a subscribe option to keep up with what just shipped.
Can I browse the Truestamp knowledge base?
Yes. The knowledge base has its own section of the site at www.truestamp.com/knowledge, and the support page links straight to it. It lets you search the concepts behind Truestamp, browse them by subject area or by tag, read a concept, and follow the links between related concepts (its prerequisites, related reading, and which other concepts reference the one you are viewing) to explore how everything fits together. It is the same knowledge base that answers questions in the in-app AI chat assistant, here in a browse-and-read form.
No sign-in is required, and what you can see is scoped to who you are: a signed-out visitor sees the public concepts, and signing in surfaces additional concepts written for members. Searching happens on the knowledge base itself, and everything you can browse to has an address of its own: each subject area, each tag, and each concept.
Can I link to a single knowledge base concept?
Yes. Every concept has its own page, and its address is its name in the knowledge base: the concept “Item Lifecycle”, filed under Items, is at www.truestamp.com/knowledge/items/item-lifecycle. Two shorter forms sit above it: www.truestamp.com/knowledge lists every subject area, and www.truestamp.com/knowledge/items lists the concepts in one of them. Tags are addressable the same way: www.truestamp.com/knowledge/tags lists every tag, and each tag has a page listing the concepts that carry it.
Each section heading within a concept is addressable too, by adding # and the
section’s name to the concept’s address, so a link can point at the exact paragraph
that answers a question rather than at the top of a long page.
These pages are ordinary, shareable, bookmarkable links. They need no account, and a link you send someone shows them the same concept you were reading, as long as it is one their account is allowed to see. An address that names a concept you may not read is answered the same way as an address that names nothing at all.
How do I report a security vulnerability?
Email [email protected]. Truestamp runs a responsible disclosure program, and the Reporting Security Issues section of the security page states its terms:
- In scope: the web application at www.truestamp.com, the public API, and the verification tools and libraries Truestamp publishes.
- Out of scope: scanner output with no demonstrated impact, denial of service and volumetric testing, social engineering of staff or customers, physical access attempts, and services operated by third parties.
- Safe harbor: Truestamp will not pursue legal action over good-faith research that stays in scope, uses only the researcher’s own accounts and test data, stops at a proof of concept, and neither disrupts the service nor exposes anyone else’s data.
- What to expect: acknowledgement within three business days, with word on whether the report reproduced and what Truestamp plans to do, and a request to hold publication for 90 days or a shorter agreed window.
The same contact is published two more ways so automated tooling and researchers can find it: on the support page’s “Security Issues” card, and in the machine-readable disclosure file at www.truestamp.com/.well-known/security.txt. Use the security address only for vulnerabilities; general questions belong at [email protected].
What is the security.txt file?
/.well-known/security.txt is a plain-text vulnerability disclosure file served at
the standard well-known location defined by RFC 9116, so security researchers and
scanners can discover the right contact without guessing. The same file is also
served at the top-level www.truestamp.com/security.txt,
the older location RFC 9116 still permits for compatibility, for tooling that looks
there first. Both paths return the identical body rather than a redirect, and the
Canonical field inside it names the well-known path as the authoritative one.
Truestamp’s file declares:
Contact: mailto:[email protected]Policy: https://www.truestamp.com/security#reporting (the disclosure terms on the security page, deep-linked rather than the top of the page)Canonical: https://www.truestamp.com/.well-known/security.txtPreferred-Languages: enExpires: a date 180 days in the future, regenerated on every request so the file never goes stale
What does the security page cover?
The public security page at www.truestamp.com/security summarizes Truestamp’s security posture for a general audience: the cryptographic foundations (SHA-256 hashing, Ed25519 signatures with a published signing public key, Merkle trees, and tamper-evident ledger records that stay verifiable even after you redact your submitted data), data protection practices (files hashed in the browser and never uploaded, submitted claims stored only until redacted or deleted, only hash values reaching any blockchain, TLS in transit, revocable API keys, role-based access), account security (passkeys, two-factor codes, recovery codes, the security activity log on your profile, and revocable authorization for connected applications), infrastructure and operational security, the disclosure program terms described above, and the transparency model in which every timestamp can be independently verified offline. It closes with the vulnerability-reporting instructions described above. For the precise statement of the cryptographic guarantees themselves, see what Truestamp proves.
Where can I find self-serve help?
Before emailing support, three public resources answer most questions:
- The Knowledge Base at www.truestamp.com/knowledge: browse the concepts behind Truestamp by subject or by tag, follow the links between them, or search them from the box at the top of the page.
- API documentation at www.truestamp.com/api: guides for the REST and GraphQL APIs, including interactive documentation and code examples.
- The FAQ on the home page at www.truestamp.com/#faq: quick answers to the most common questions about timestamping and verification.
For checking a proof you already hold, the walkthrough in verify a proof covers the public verification page. For the terms of service, privacy policy, and other legal documents, see legal documents.
Citations
- RFC 9116: A File Format to Aid in Security Vulnerability Disclosure. Defines the
/.well-known/security.txtlocation and the Contact, Expires, Preferred-Languages, Canonical, and Policy fields Truestamp’s file uses.