Synthetic evaluation only
Public workflows use fixed fictional or synthetic records. They do not require a customer-data upload or establish a production service.

THONIS TRUST CENTER
This center consolidates THONIS security, privacy, legal, deployment, responsible-disclosure, and product-evidence boundaries. Public material is available without an account; customer-specific architecture, data, controls, and confidential artifacts require an approved engagement and disclosure path.
Transparency without borrowed credibility. No SOC 2 report, ISO certificate, FedRAMP authorization, or independent penetration-test report is currently published. THONIS will not display a badge or claim until the exact scope and evidence support it.
Current posture
Public workflows use fixed fictional or synthetic records. They do not require a customer-data upload or establish a production service.
Each product separates current software evidence from the end-to-end product destination and from customer-specific production acceptance.
Do not send or upload CUI, classified material, credentials, regulated records, controlled technical data, personal data, or sensitive evidence through public paths.
Publication, deployment, connector writes, submissions, account changes, and company-page engagement require explicit authority and verified read-back.
Trust resources
Architecture principles, AI authority, data boundaries, integrity, validation, and customer responsibilities.
Open this resourceEvidence, deterministic gates, human authority, model use, data rights, lifecycle testing, and change boundaries.
Open this resourceWebsite, public-evaluation, email, customer-data, model-use, access, correction, and deletion boundaries.
Open this resourceThe live security-cookie inventory and the approval gate before analytics or other non-essential measurement is activated.
Open this resourceCurrent public proof, scoped-pilot criteria, deployment profiles, connector gates, read-back, recovery, and exit requirements.
Open this resourceWebsite terms, evaluation boundaries, intellectual-property, controlled-data, export, third-party, and contract boundaries.
Open this resourceA bounded path for reporting suspected vulnerabilities in THONIS-controlled public assets without exposing customer or sensitive data.
Open this resourcePlain-English definitions for the security, legal, assurance, technical-data, architecture, autonomy, and evidence terms used across THONIS.
Open this resourceTrust artifacts and availability
Security and AI principles, privacy and cookie notices, deployment boundaries, standards/applicability guidance, accessibility statement, legal/evaluation boundaries, responsible disclosure, and public synthetic workflows.
Data maps, system boundaries, threat models, control matrices, architecture decisions, connector permissions, model-use terms, retention, incident routes, acceptance tests, and exit requirements are created for the approved case.
No SOC 2 report, ISO certificate, FedRAMP authorization, independent penetration-test report, cyber-insurance certificate, SLA, DPA, or blanket production-security addendum is represented as complete or generally available.
Company-wide control principles
Begin read-only. Add a write only when its preview, accountable approval, idempotency, acknowledgement, read-back, retry, and recovery behavior are specified and tested.
Models may retrieve, compare, classify, summarize, or draft. Deterministic controls and named people decide whether a consequential result is accepted, released, or executed.
A hash can reveal change; a signature can bind identity and bytes; a passing test can prove one scenario. None alone proves truth, legal authority, compliance, interoperability, or customer acceptance.
Unknown applicability, stale sources, failed validation, ambiguous writes, unavailable controls, and mismatched read-back block, reopen, or escalate the affected work.
Customer records, evidence, decisions, logs, configuration, keys, backups, and integrations need documented ownership, export, deletion, and exit tests.
Threat modeling, dependency review, secret exclusion, least privilege, code review, automated tests, vulnerability scanning, remediation evidence, and release integrity are product requirements—not add-on marketing claims.
Data, subprocessors, and operations
Hosting and network providers process connection data needed to deliver and secure the site. Cloudflare may set an essential bot-protection cookie. Consent-gated Google Analytics and sitewide content-masked Microsoft Clarity load only after the visitor allows their separate categories. No inquiry text is sent as an analytics event. No advertising or retargeting pixel currently loads, and browser fingerprinting is not used.
Review cookies and measurementTHONIS has not published a production-customer subprocessor register because no generally available hosted Dextra service is represented here. Before a customer-data service begins, the parties identify the actual providers, functions, locations, access, transfer, security, incident, retention, deletion, and change-notification terms.
No blanket production SLA, RTO, RPO, disaster-recovery test, or high-availability attestation is published. A pilot or production agreement must identify the selected deployment, dependencies, backups, failover, restoration, support, communications, tests, and evidence.
Suspected issues in THONIS-controlled public assets use the responsible-disclosure path. Customer incident ownership, notification timing, evidence preservation, regulatory duties, and secure communications are defined in the signed engagement.
Product evidence register
Working local product mechanics and public synthetic workflows support scoped assurance cases. They do not prove customer deployment, independent assessment, certification, authorization, or universal regulatory applicability.
Working local technical-content mechanics and a public synthetic workflow support source-linked review and controlled handoff. They do not prove official standards conformance, destination acceptance, deployed connectors, or customer results.
A working local synthetic proof supports whole-system understanding, correction, questions, semantic-baseline compilation, synchronized views, and change propagation. It does not prove production model-repository integration or accepted program architecture.
A working local software prototype supports signed proposal checks, deterministic policy, attributable approval, pre-dispatch re-check, simulated dispatch, and a tamper-evident local trail. It does not prove hardware flight, airworthiness, field use, production interoperability, certification, or operational authorization.
Primary external foundations
Zero Trust Architecture explains why identity, assets, and resources—not network location alone—must control access.
Secure Software Development Framework provides a common vocabulary for reducing software-vulnerability risk throughout development.
Secure by Design places responsibility for secure outcomes, transparency, and safe defaults on technology manufacturers.
Reference to a framework means it informed the stated principle. It does not mean THONIS or a Dextra product is assessed, certified, compliant, authorized, or endorsed under that framework.
BUYER DUE DILIGENCE
Start with the product, data types, users, systems, deployment boundary, applicable requirements, decision authority, and artifacts needed to close your review. Do not email sensitive evidence before a secure exchange path is agreed.
Ask a trust question