LEGAL
Vulnerability disclosure policy
How to report a security flaw in anything we run, and what we will do about it. Machine-readable at /.well-known/security.txt, as RFC 9116 defines it.
How to report
Write to info@thz.net. Say what you found, where, and the steps to reproduce it. A proof of concept helps; a scanner report on its own usually does not.
If the finding is being actively exploited, call +386 51 249 533 as well. Do not wait for a reply to the email.
What we do with it
We acknowledge every report within three working days, tell you whether we consider it a vulnerability, and keep you informed until it is closed.
We will not take legal action against anyone who reports in good faith under this policy, and we will credit you when the fix ships, unless you would rather we did not.
What we ask of you
Give us reasonable time to fix it before you publish. Do not access, change or delete data that is not yours, do not degrade the service for anyone else, and do not use social engineering against our staff or clients.
Testing that amounts to a denial-of-service attempt, spam, or physical intrusion is outside this policy.
Scope
Domains and services operated by THZ Networks. A finding in a client system reached through us belongs to that client — tell us and we will route it, but do not test it without their authorisation.
Last reviewed 14 September 2026.