THEION / RESPONSIBLE DISCLOSURE / PUBLIC WEBSITE

A clear channel for responsible security reports.

If you identify a possible vulnerability in the THEION institutional website, report the smallest useful set of facts privately. The objective is to understand and reduce risk without increasing the exposure.

RESPONSIBLE DISCLOSURE PATH

Reduce impact first. Preserve enough context to act.

A useful report is specific, private and proportionate. It distinguishes an observation from permission to continue testing.

01

Minimize impact

Stop before an observation becomes access, disruption, alteration or unnecessary exposure.

02

Record context

Preserve the affected URL, observed behavior, minimal reproduction steps and potential impact.

03

Report privately

Use the institutional channel without publishing exploitable details or unnecessary sensitive data.

04

Support triage

Answer bounded questions needed to identify ownership, reproduce the issue and assess severity.

05

Verify closure

Correction, disclosure timing and any public credit require case-specific coordination.

OUT OF SCOPE

Do not turn a report into additional risk.

The public reporting channel is intentionally narrow. It is not an invitation to attack availability, people, data or infrastructure.

X1

Availability attacks

No denial of service, destructive testing, excessive traffic or resource exhaustion.

X2

Human targeting

No social engineering, phishing, impersonation or contact with staff, clients or partners.

X3

Persistence or expansion

No persistence, privilege escalation, lateral movement, data extraction or destructive action.

X4

Third-party systems

No indiscriminate scanning or testing of hosting, email, DNS, social platforms or other providers.

OPERATING BOUNDARIES

Scope and authority remain explicit throughout the case.

These rules protect the reporter, visitors, THEION and third parties by preventing silent expansion of the investigation.

S1Scope

The channel covers observations concerning https://theionintegratedprojects.com and files served from that origin. Third-party services remain governed by their owners’ programs and policies.

S2What to include

Provide the affected URL, an objective description, minimal steps, potential impact and evidence that does not expose credentials, personal data or third-party content.

S3Protect people and systems

Do not access, alter, delete, download or share third-party data. Stop immediately if further investigation could increase impact.

S4No implied authorization

This page and security.txt do not authorize invasive testing, bypassing controls, social engineering, denial of service or access beyond what is necessary to report an already observed condition.

S5Triage and treatment

When the report can be located, review may separate asset, version, reproduction, impact, exposure and priority; THEION may request context, contain risk, involve the responsible provider and verify a correction.

S6Coordination

Public disclosure, timing, attribution and credit depend on explicit case-specific agreement. Receipt, an automated response or silence does not constitute approval.

S7Channel limits

This is not a bug bounty program, reward promise, contract, broad safe harbor or guaranteed remediation timeline. Handling depends on reproducibility, impact, asset ownership and applicable obligations.

DISCOVERY STANDARD

security.txt makes the reporting channel machine-discoverable.

THEION publishes the standard location for security-contact information. The document identifies a channel; it does not enlarge testing authority.

Read RFC 9116

Keep the first report controlled and reviewable.

Do not include passwords, tokens, personal records, confidential files or exploit material beyond what is necessary to identify the issue.

Review THEION trust and assurance boundaries

PRIVATE REPORTING CHANNEL

Send the smallest complete report.

The button prepares a draft to vitor@theionintegratedprojects.com in your email application. Review it and remove unnecessary sensitive information before choosing to send.

Prepare a security report