RESPONSIBLE DISCLOSURE
Report a suspected vulnerability without expanding the harm.
THONIS welcomes good-faith reports about THONIS-controlled public assets. Stop when you have enough evidence to explain the issue, avoid sensitive data, and let THONIS establish a safer channel before sending exploit code, secrets, personal data, or non-public system detail.
No customer or third-party testing is authorized. This policy cannot authorize activity against infrastructure THONIS does not own or control.
Before you report
Minimize access, impact, and disclosure.
Use the least invasive method that can establish the issue. Do not access more records than necessary, change or delete data, pivot, establish persistence, obtain shell access when a safer proof exists, disrupt availability, or retain any data. If sensitive information appears, stop, record only the minimum non-sensitive locator, and report immediately.
Scope
Know what this policy covers.
IN SCOPETHONIS-controlled public assets
- thonissystems.com and public subpaths demonstrably controlled by THONIS
- Public synthetic Dextra demonstrations hosted on a THONIS-controlled domain
- A THONIS-owned public repository only when its own security policy identifies it as in scope
OUT OF SCOPECustomer, third-party, disruptive, and deceptive activity
- Customer, prospect, partner, Government, or third-party systems and data
- LinkedIn, email, hosting, DNS, analytics, model, package-registry, or other provider infrastructure
- Private repositories, local developer machines, employee accounts, physical premises, or social engineering
- Denial of service, volumetric testing, destructive testing, malware, persistence, spam, automated credential attacks, or supply-chain attacks
- Findings that depend only on unsupported software, absent best-practice headers without impact, self-XSS, or previously public information without a new exploitable condition
What to include
Give THONIS enough to reproduce the issue safely.
01 · LOCATIONAsset and entry point
The exact public URL, route, component, and time observed. Do not send credentials, tokens, cookies, customer identifiers, or data dumps.
02 · IMPACTSecurity consequence
Explain what an unauthorized party could read, change, execute, bypass, impersonate, or disrupt and the preconditions required.
03 · REPRODUCTIONMinimal safe steps
List deterministic steps, expected versus actual behavior, browser or client version, and a redacted screenshot or harmless request when useful.
04 · EXTENTWhat you accessed
State exactly what was tested and whether any data appeared. Confirm deletion of locally retained sensitive data once THONIS says preservation is no longer needed.
05 · CONTACTSafe follow-up
Provide an email address and any preferred encryption method. Anonymous reports are accepted but can make clarification and coordinated disclosure harder.
06 · COORDINATIONDo not publish exploitable detail yet
Allow reasonable time for validation and remediation. THONIS will discuss a disclosure timeline after impact and affected parties are understood; no fixed response SLA is represented.
Good-faith handling
Research that stays inside this policy should not create unnecessary conflict.
THONIS does not intend to pursue legal action solely for good-faith research that stays within this scope, avoids privacy and operational harm, complies with applicable law, stops after minimum proof, reports promptly, and supports coordinated remediation. This statement does not bind third parties, waive rights for extortion, data misuse, disruption, unlawful conduct, or policy violations, and is not legal advice.
Use the security contact for the first non-sensitive report.
Email the asset, impact, and minimum reproduction outline. THONIS will establish a safer exchange method if additional technical material is required.
Report a suspected vulnerability