Responsible Disclosure Policy
How to report a security vulnerability and what to expect from us.
1. Our Commitment
As a managed cybersecurity company, we hold ourselves to the same standard we set for our clients. If you discover a security vulnerability in any Threvol Technologies LLC system, website or service, we want to know. We commit to working with you in good faith to understand and resolve the issue quickly.
2. How to Report
Send your report by email to: [email protected]
Please include:
- A clear description of the vulnerability and its potential impact
- The affected system or URL
- Steps to reproduce the issue
- Any relevant screenshots, logs or proof-of-concept code (for technical clarity only)
- Your contact information if you wish to receive updates
You may submit reports anonymously if you prefer. Anonymous reports will still be investigated, but we will not be able to follow up with you directly.
3. What to Expect
| Milestone | Commitment |
|---|---|
| Initial acknowledgment | Within 48 business hours |
| Severity assessment | Within 5 business days |
| Status update | Every 10 business days until resolved |
| Resolution target | Within 90 days for most findings; critical issues prioritized |
| Disclosure coordination | We will discuss public disclosure timing with you before any announcement |
4. Safe Harbor
Threvol Technologies LLC will not pursue civil or criminal action against researchers who discover and report security vulnerabilities in good faith, provided that you:
- Do not access, modify, delete or exfiltrate data beyond what is strictly necessary to demonstrate the vulnerability
- Do not disrupt or degrade our services or those of our clients
- Do not exploit the vulnerability for any purpose other than reporting it to us
- Do not disclose the vulnerability publicly before we have had a reasonable opportunity to resolve it
- Do not engage in social engineering, phishing or physical security testing against our staff or clients
We consider good-faith security research to be a valuable contribution to our security posture and the broader community.
5. Out of Scope
The following are outside the scope of this policy:
- Denial-of-service (DoS or DDoS) attacks of any kind
- Spam or social engineering directed at our employees, partners or clients
- Physical security testing (attempting access to offices, hardware or infrastructure)
- Automated scanning that generates excessive server load
- Vulnerabilities in third-party services we use but do not control (please report those directly to the vendor)
- Reports based purely on theoretical risks with no demonstrated impact
6. Recognition
We acknowledge researchers who report valid, in-scope vulnerabilities. If you would like to be credited by name in our internal security acknowledgments, let us know in your report. We currently do not offer financial compensation (bug bounty), but we are grateful for responsible disclosures and will acknowledge your contribution.
7. Contact
Security reports: [email protected]
General inquiries: [email protected]