THONIS TRUST CENTER

Trust should be inspectable before sensitive work begins.

This center consolidates THONIS security, privacy, legal, deployment, responsible-disclosure, and product-evidence boundaries. Public material is available without an account; customer-specific architecture, data, controls, and confidential artifacts require an approved engagement and disclosure path.

Transparency without borrowed credibility. No SOC 2 report, ISO certificate, FedRAMP authorization, or independent penetration-test report is currently published. THONIS will not display a badge or claim until the exact scope and evidence support it.

What a buyer can rely on today.

PUBLIC WEBSITE

Synthetic evaluation only

Public workflows use fixed fictional or synthetic records. They do not require a customer-data upload or establish a production service.

PRODUCTS

Working prototypes, bounded claims

Each product separates current software evidence from the end-to-end product destination and from customer-specific production acceptance.

CUSTOMER DATA

No unapproved intake

Do not send or upload CUI, classified material, credentials, regulated records, controlled technical data, personal data, or sensitive evidence through public paths.

EXTERNAL ACTIONS

Human approval remains required

Publication, deployment, connector writes, submissions, account changes, and company-page engagement require explicit authority and verified read-back.

Security, AI, privacy, legal, and technical answers in one place.

01

Security posture

Architecture principles, AI authority, data boundaries, integrity, validation, and customer responsibilities.

Open this resource
02

AI governance and human authority

Evidence, deterministic gates, human authority, model use, data rights, lifecycle testing, and change boundaries.

Open this resource
03

Privacy and data handling

Website, public-evaluation, email, customer-data, model-use, access, correction, and deletion boundaries.

Open this resource
04

Cookies and measurement

The live security-cookie inventory and the approval gate before analytics or other non-essential measurement is activated.

Open this resource
05

Deployment and integration

Current public proof, scoped-pilot criteria, deployment profiles, connector gates, read-back, recovery, and exit requirements.

Open this resource
06

Legal center

Website terms, evaluation boundaries, intellectual-property, controlled-data, export, third-party, and contract boundaries.

Open this resource
07

Responsible disclosure

A bounded path for reporting suspected vulnerabilities in THONIS-controlled public assets without exposing customer or sensitive data.

Open this resource
08

Trust and technical glossary

Plain-English definitions for the security, legal, assurance, technical-data, architecture, autonomy, and evidence terms used across THONIS.

Open this resource

Publish only what exists. Gate what is confidential.

PUBLIC NOW

Evaluation and policy material

Security and AI principles, privacy and cookie notices, deployment boundaries, standards/applicability guidance, accessibility statement, legal/evaluation boundaries, responsible disclosure, and public synthetic workflows.

CUSTOMER-SCOPED

Engagement-specific evidence

Data maps, system boundaries, threat models, control matrices, architecture decisions, connector permissions, model-use terms, retention, incident routes, acceptance tests, and exit requirements are created for the approved case.

NOT CURRENTLY PUBLISHED

Independent assurance reports

No SOC 2 report, ISO certificate, FedRAMP authorization, independent penetration-test report, cyber-insurance certificate, SLA, DPA, or blanket production-security addendum is represented as complete or generally available.

The same safeguards apply across every Dextra product.

MINIMUM ACCESS

Authorize exact records, identities, fields, and actions

Begin read-only. Add a write only when its preview, accountable approval, idempotency, acknowledgement, read-back, retry, and recovery behavior are specified and tested.

AI BOUNDARY

AI assists; accountable people retain consequential authority

Models may retrieve, compare, classify, summarize, or draft. Deterministic controls and named people decide whether a consequential result is accepted, released, or executed.

EVIDENCE INTEGRITY

State exactly what a mechanism proves

A hash can reveal change; a signature can bind identity and bytes; a passing test can prove one scenario. None alone proves truth, legal authority, compliance, interoperability, or customer acceptance.

FAIL VISIBLE

Missing evidence keeps the work open

Unknown applicability, stale sources, failed validation, ambiguous writes, unavailable controls, and mismatched read-back block, reopen, or escalate the affected work.

PORTABILITY + EXIT

Define export, retention, deletion, and transition up front

Customer records, evidence, decisions, logs, configuration, keys, backups, and integrations need documented ownership, export, deletion, and exit tests.

SECURE DEVELOPMENT

Build security into design and verification

Threat modeling, dependency review, secret exclusion, least privilege, code review, automated tests, vulnerability scanning, remediation evidence, and release integrity are product requirements—not add-on marketing claims.

Production terms follow the actual data flow.

Public website

Hosting and network providers process connection data needed to deliver and secure the site. Cloudflare may set an essential bot-protection cookie. Consent-gated Google Analytics and sitewide content-masked Microsoft Clarity load only after the visitor allows their separate categories. No inquiry text is sent as an analytics event. No advertising or retargeting pixel currently loads, and browser fingerprinting is not used.

Review cookies and measurement

Subprocessor register

THONIS has not published a production-customer subprocessor register because no generally available hosted Dextra service is represented here. Before a customer-data service begins, the parties identify the actual providers, functions, locations, access, transfer, security, incident, retention, deletion, and change-notification terms.

Business continuity

No blanket production SLA, RTO, RPO, disaster-recovery test, or high-availability attestation is published. A pilot or production agreement must identify the selected deployment, dependencies, backups, failover, restoration, support, communications, tests, and evidence.

Incident handling

Suspected issues in THONIS-controlled public assets use the responsible-disclosure path. Customer incident ownership, notification timing, evidence preservation, regulatory duties, and secure communications are defined in the signed engagement.

One company trust doctrine, four separate product evidence boundaries.

DEXTRA

AssuranceOps

Working local product mechanics and public synthetic workflows support scoped assurance cases. They do not prove customer deployment, independent assessment, certification, authorization, or universal regulatory applicability.

DEXTRA

TRACE

Working local technical-content mechanics and a public synthetic workflow support source-linked review and controlled handoff. They do not prove official standards conformance, destination acceptance, deployed connectors, or customer results.

DEXTRA

SyntheSys

A working local synthetic proof supports whole-system understanding, correction, questions, semantic-baseline compilation, synchronized views, and change propagation. It does not prove production model-repository integration or accepted program architecture.

DEXTRA

Sentinel

A working local software prototype supports signed proposal checks, deterministic policy, attributable approval, pre-dispatch re-check, simulated dispatch, and a tamper-evident local trail. It does not prove hardware flight, airworthiness, field use, production interoperability, certification, or operational authorization.

Frameworks inform the safeguards; they do not certify THONIS.

ZERO TRUST

NIST SP 800-207

Zero Trust Architecture explains why identity, assets, and resources—not network location alone—must control access.

SECURE BY DESIGN

CISA guidance

Secure by Design places responsibility for secure outcomes, transparency, and safe defaults on technology manufacturers.

Reference to a framework means it informed the stated principle. It does not mean THONIS or a Dextra product is assessed, certified, compliant, authorized, or endorsed under that framework.

Ask for the evidence that matches the exact deployment and decision.

Start with the product, data types, users, systems, deployment boundary, applicable requirements, decision authority, and artifacts needed to close your review. Do not email sensitive evidence before a secure exchange path is agreed.

Ask a trust question