Minimize impact
Stop before an observation becomes access, disruption, alteration or unnecessary exposure.
THEION / RESPONSIBLE DISCLOSURE / PUBLIC WEBSITE
If you identify a possible vulnerability in the THEION institutional website, report the smallest useful set of facts privately. The objective is to understand and reduce risk without increasing the exposure.
RESPONSIBLE DISCLOSURE PATH
A useful report is specific, private and proportionate. It distinguishes an observation from permission to continue testing.
Stop before an observation becomes access, disruption, alteration or unnecessary exposure.
Preserve the affected URL, observed behavior, minimal reproduction steps and potential impact.
Use the institutional channel without publishing exploitable details or unnecessary sensitive data.
Answer bounded questions needed to identify ownership, reproduce the issue and assess severity.
Correction, disclosure timing and any public credit require case-specific coordination.
OUT OF SCOPE
The public reporting channel is intentionally narrow. It is not an invitation to attack availability, people, data or infrastructure.
No denial of service, destructive testing, excessive traffic or resource exhaustion.
No social engineering, phishing, impersonation or contact with staff, clients or partners.
No persistence, privilege escalation, lateral movement, data extraction or destructive action.
No indiscriminate scanning or testing of hosting, email, DNS, social platforms or other providers.
OPERATING BOUNDARIES
These rules protect the reporter, visitors, THEION and third parties by preventing silent expansion of the investigation.
The channel covers observations concerning https://theionintegratedprojects.com and files served from that origin. Third-party services remain governed by their owners’ programs and policies.
Provide the affected URL, an objective description, minimal steps, potential impact and evidence that does not expose credentials, personal data or third-party content.
Do not access, alter, delete, download or share third-party data. Stop immediately if further investigation could increase impact.
This page and security.txt do not authorize invasive testing, bypassing controls, social engineering, denial of service or access beyond what is necessary to report an already observed condition.
When the report can be located, review may separate asset, version, reproduction, impact, exposure and priority; THEION may request context, contain risk, involve the responsible provider and verify a correction.
Public disclosure, timing, attribution and credit depend on explicit case-specific agreement. Receipt, an automated response or silence does not constitute approval.
This is not a bug bounty program, reward promise, contract, broad safe harbor or guaranteed remediation timeline. Handling depends on reproducibility, impact, asset ownership and applicable obligations.
DISCOVERY STANDARD
THEION publishes the standard location for security-contact information. The document identifies a channel; it does not enlarge testing authority.
Read RFC 9116Do not include passwords, tokens, personal records, confidential files or exploit material beyond what is necessary to identify the issue.
Review THEION trust and assurance boundariesPRIVATE REPORTING CHANNEL
The button prepares a draft to vitor@theionintegratedprojects.com in your email application. Review it and remove unnecessary sensitive information before choosing to send.
Prepare a security report