Report suspected vulnerabilities through the owner-approved private THOX.ai LLC security channel or GitHub private vulnerability reporting when enabled for this repository.
Do not disclose suspected vulnerabilities publicly until THOX.ai LLC has triaged and remediated them.
This policy covers THOX-specific code, configuration, documentation, scripts, product definitions, and release artifacts in this repository. Third-party and upstream components remain subject to their original maintainers' vulnerability handling processes.
THOX.ai LLC maintains this repository. Tommy Xaypanya is CTO. Craig Ross is CEO.
Copyright (c) 2026 THOX.ai LLC. All rights reserved unless a repository-specific license states otherwise.