Responsible disclosure
How to report a vulnerability or a safety concern, and what you can expect from us.
Email contact@theoratix.ai with a description of the issue, the steps to reproduce it and any proof of concept. Please give us a reasonable time to fix it before you share it publicly. Our contact details are also published at /.well-known/security.txt.
Scope
theoratix.ai and the services we operate under it. Services run by other companies (for example our hosting or email providers) are out of scope; please report issues in them to those companies.
What we ask
- Only test against your own accounts and data. Do not access, change or delete data that is not yours, and stop as soon as you reach any.
- Do not degrade our services, and do not run denial-of-service or high-volume automated tests.
- Do not use social engineering, phishing or physical attacks.
- Keep the details confidential until we have fixed the issue or agreed a date with you.
What you can expect
- A reply from a person, which we aim to send within three business days.
- Updates while we investigate and fix the issue.
- Credit for the finding once it is fixed, if you would like it.
- We will not pursue legal action against research done in good faith and in line with this policy.