Please report suspected vulnerabilities privately by emailing hello@thalovant.com.
Do not open a public issue, discussion or pull request for a suspected vulnerability. Include:
- the affected repository, package or service, and its version;
- what you observed and the smallest steps that reproduce it;
- the impact you think it has.
Do not include real credentials, customer data or private exploit details in public channels, and please test only against systems and accounts you own.
- We acknowledge a report within two business days.
- We confirm or dismiss it after triage and tell you which, with our reasoning.
- For a confirmed issue we share a fix timeline that depends on severity, keep you updated until it ships, and credit you in the advisory if you wish.
- Please give us a reasonable time to ship a fix before you disclose publicly.
This organization-level policy applies to every Thalovant repository that does
not carry its own SECURITY.md, and to the Thalovant services at thalovant.com,
dash.thalovant.com and docs.thalovant.com. Vulnerabilities in an upstream project
we fork (for example OpenVoiceOS or HiveMind) are best reported to that project
as well.