Coordinated disclosure

Security

Report suspected vulnerabilities to info@zenitgroup.com.co. ThermalGlobe does not currently offer a bug bounty.

What to include

  • Affected URL or component.
  • Reproduction steps with minimal non-sensitive evidence.
  • Expected impact.
  • A safe contact route for follow-up.

Please avoid

  • Accessing or altering other people’s data.
  • Denial of service, broad automated scanning, social engineering, or physical intrusion.
  • Publishing exploitable details before the operator has had a reasonable opportunity to investigate.

Machine-readable policy

The canonical security contact is also published at /.well-known/security.txt. Receipt is not a promise of reward, safe-harbour terms, or a specific resolution time.