RESPONSIBLE DISCLOSURE

Report a suspected vulnerability without expanding the harm.

THONIS welcomes good-faith reports about THONIS-controlled public assets. Stop when you have enough evidence to explain the issue, avoid sensitive data, and let THONIS establish a safer channel before sending exploit code, secrets, personal data, or non-public system detail.

No customer or third-party testing is authorized. This policy cannot authorize activity against infrastructure THONIS does not own or control.

Minimize access, impact, and disclosure.

Use the least invasive method that can establish the issue. Do not access more records than necessary, change or delete data, pivot, establish persistence, obtain shell access when a safer proof exists, disrupt availability, or retain any data. If sensitive information appears, stop, record only the minimum non-sensitive locator, and report immediately.

Know what this policy covers.

IN SCOPE

THONIS-controlled public assets

  • thonissystems.com and public subpaths demonstrably controlled by THONIS
  • Public synthetic Dextra demonstrations hosted on a THONIS-controlled domain
  • A THONIS-owned public repository only when its own security policy identifies it as in scope
OUT OF SCOPE

Customer, third-party, disruptive, and deceptive activity

  • Customer, prospect, partner, Government, or third-party systems and data
  • LinkedIn, email, hosting, DNS, analytics, model, package-registry, or other provider infrastructure
  • Private repositories, local developer machines, employee accounts, physical premises, or social engineering
  • Denial of service, volumetric testing, destructive testing, malware, persistence, spam, automated credential attacks, or supply-chain attacks
  • Findings that depend only on unsupported software, absent best-practice headers without impact, self-XSS, or previously public information without a new exploitable condition

Give THONIS enough to reproduce the issue safely.

01 · LOCATION

Asset and entry point

The exact public URL, route, component, and time observed. Do not send credentials, tokens, cookies, customer identifiers, or data dumps.

02 · IMPACT

Security consequence

Explain what an unauthorized party could read, change, execute, bypass, impersonate, or disrupt and the preconditions required.

03 · REPRODUCTION

Minimal safe steps

List deterministic steps, expected versus actual behavior, browser or client version, and a redacted screenshot or harmless request when useful.

04 · EXTENT

What you accessed

State exactly what was tested and whether any data appeared. Confirm deletion of locally retained sensitive data once THONIS says preservation is no longer needed.

05 · CONTACT

Safe follow-up

Provide an email address and any preferred encryption method. Anonymous reports are accepted but can make clarification and coordinated disclosure harder.

06 · COORDINATION

Do not publish exploitable detail yet

Allow reasonable time for validation and remediation. THONIS will discuss a disclosure timeline after impact and affected parties are understood; no fixed response SLA is represented.

Research that stays inside this policy should not create unnecessary conflict.

THONIS does not intend to pursue legal action solely for good-faith research that stays within this scope, avoids privacy and operational harm, complies with applicable law, stops after minimum proof, reports promptly, and supports coordinated remediation. This statement does not bind third parties, waive rights for extortion, data misuse, disruption, unlawful conduct, or policy violations, and is not legal advice.

Use the security contact for the first non-sensitive report.

Email the asset, impact, and minimum reproduction outline. THONIS will establish a safer exchange method if additional technical material is required.

Report a suspected vulnerability