We welcome reports from security researchers. If you believe you have found a vulnerability in a Theona system, this page explains how to report it and what you can expect from us in return.
The security of our customers' data is fundamental to how we operate. No system is perfect, and the security research community plays an important role in helping us keep Theona safe. This policy describes how to report a suspected vulnerability, what is in and out of scope, and the commitments we make to researchers who work with us in good faith.
We will investigate every legitimate report, work to remediate confirmed issues within the timelines below, and treat researchers who follow this policy as trusted partners rather than adversaries.
We consider research conducted in line with this policy to be authorized, lawful, and helpful. Acting in good faith means making an honest effort to avoid harm to our users, our data, and the availability of our services, and giving us a reasonable opportunity to respond before sharing your findings with anyone else.
Send your report to[email protected]. To help us triage quickly, please include:
A machine-readable version of our security contact is published at/.well-known/security.txtin line with RFC 9116.
The following are not covered by this policy. Reports limited to these will generally be closed without action:
If you make a good-faith effort to comply with this policy during your research, we will consider your testing to be authorized, we will not pursue or support legal action against you, and we will not ask you to be subject to action under our Terms of Service provisions that would otherwise restrict security testing.
This authorization is limited to the systems listed as in scope and to activity that follows the rules of engagement below. It does not give you permission to access, modify, or destroy data that is not your own, and it does not waive any rights of third parties. If legal action is initiated by a third party against you for activity that complied with this policy, we will make this authorization known.
When testing, you must:
We ask that you give us a reasonable opportunity to investigate and remediate a reported issue before disclosing it publicly or to any third party, and that you coordinate the timing of any public disclosure with us. Reports are handled through our established security incident response process.
We will acknowledge receipt of your report within 24 hours on US business days, confirm whether we can reproduce the issue, and keep you informed as we work toward a fix. Confirmed vulnerabilities are tracked to remediation within the targets we apply across our vulnerability-management program, based on severity:
| Severity | Target remediation time |
|---|---|
| Critical | 7 days |
| High | 30 days |
| Medium | 60 days |
| Low | 90 days |
Some issues take longer to resolve safely. If remediation will exceed these targets, we will let you know and agree on a disclosure timeline with you.
This is a vulnerability disclosure program, not a bug bounty. We do not offer monetary rewards for reports. With your permission, we are glad to acknowledge your contribution once an issue has been resolved.
Your use of our services and any data you encounter remain governed by our existing policies. Nothing in this policy overrides them.
Theona, Inc. is a remote-first company registered in Delaware, USA. This policy is provided for informational purposes and does not create any legal obligations or warranties beyond those in our Terms of Service and Privacy Policy.