This English version is provided for convenience. In case of discrepancy, the French version prevails.
Version of 1 October 2026.
Do you think you have found a security vulnerability in node.this or on tyo-data.fr? Thank you for reporting it. This page explains how, and what we do next.
Scope#
- the node.this application hosted by TYO DATA (
node-this.tyo-data.fr) and its sign-in service (auth.tyo-data.fr); - the node.this software installed at a customer’s site: a vulnerability in the software concerns us; a vulnerability in the installation itself is a matter for the organisation that operates it. To test the software, use your own installation, not a customer’s;
- the tyo-data.fr website.
Out of scope: the services of our providers (host, AI model providers), to be reported to them directly.
How to report#
Write to security@tyo-data.fr. So that we can analyse and reproduce the problem, please include as much of the following as you can:
- what is affected: the address, the endpoint, the feature or the version concerned;
- how to reproduce the problem, step by step;
- the conditions required to exploit it: an account, a role, a particular setting;
- what an attacker could do with it, in your view;
- a proof of concept, if you have one;
- any useful screenshots or logs;
- your recommendation, if you have one.
You may write in French or in English. Do not attach any personal data you may have obtained by exploiting the vulnerability.
A report that is only the output of an automated tool, with no verification and no context, may be set aside.
We do not offer an encryption key (PGP or otherwise): your message reaches us in the clear. If your report is particularly sensitive, you may go through ANSSI, the French national cybersecurity agency, rather than through us (see below): it forwards reports without disclosing your identity.
What we commit to doing#
- acknowledge your report within 3 business days;
- give you a first assessment within 10 business days: is the vulnerability confirmed, and how severe is it;
- treat your report confidentially;
- keep you informed until it is fixed, and tell you when it is;
- fix confirmed vulnerabilities within a reasonable time, according to their severity;
- if customers’ data may have been affected, notify them, as our commitments as a processor require;
- credit you, if you wish, once the vulnerability is fixed.
We do not offer a financial reward.
What is allowed#
Within the scope described above, and provided they remain reasonable and non-destructive, the following actions are allowed:
- looking for a vulnerability and checking that it exists;
- making a limited demonstration of it;
- running tests, by hand or with tools, whose effect on the service stays low;
- collecting only the information needed to demonstrate it;
- examining the configuration and the behaviour of the application.
Limit your actions to what is strictly necessary to demonstrate the vulnerability.
Rules for good-faith research#
During your research:
- use only your own accounts, or accounts whose holder has given you consent;
- never test a node.this installation operated by a customer, not even to demonstrate a vulnerability in the software: use your own. Such an installation is not our system, and we cannot authorise anything on it;
- do not access, modify or delete other people’s data; if you access it by accident, stop, keep no copy, share none, and report it;
- do not extract data in bulk;
- do not degrade the service: no denial of service, no load testing, no mass account creation, no aggressive brute force, no credential stuffing;
- do not seek to maintain access to the system, nor to pivot towards other systems;
- do not deploy malware or a backdoor;
- do not use social engineering, phishing or physical intrusion;
- do not disclose the vulnerability publicly before it is fixed, or before the coordinated disclosure period has expired (see below).
What is out of scope#
The following reports are generally set aside, for want of a demonstrated effect:
- a missing security header, with no demonstrated impact;
- a software version visible from the outside;
- a TLS setting that could be improved, with no demonstrated exploitation;
- a recommendation about SPF, DKIM or DMARC;
- clickjacking with no realistic scenario;
- the expected public files:
robots.txt,security.txt, banners, error pages; - a theoretical problem, or one we cannot reproduce;
- the bare output of a scanner, with no verification;
- cross-site request forgery on content that is neither sensitive nor authenticated;
- account enumeration, with low impact;
- a problem specific to a browser that is no longer maintained;
- a problem that requires physical access to the machine;
- a vulnerability in a third-party service we do not operate.
This list is not exhaustive. If you believe one of these cases has a real effect on our systems, tell us: what counts is the demonstrated effect, not the category.
Coordinated disclosure#
Unless we agree otherwise, the coordinated disclosure period is 90 days from TYO DATA’s confirmation of the vulnerability. We may agree together to bring it forward, for instance if the vulnerability is fixed sooner, or to extend it if the fix requires it.
Once the vulnerability is fixed, or that period has expired, you may publish a factual technical description of it, informing us beforehand. It must contain no personal data and no customer data.
If the vulnerability also affects other software publishers or our providers, coordination may involve CERT-FR, CERT/CC, or the publishers and providers concerned.
Our commitment to good-faith researchers#
This commitment takes effect as soon as you send your report, without waiting for us to confirm the vulnerability.
Where research is conducted:
- in good faith;
- in compliance with the rules above;
- in a reasonable and proportionate manner;
- and in compliance with applicable laws;
TYO DATA regards it as authorised. On that basis, TYO DATA commits to:
- not file a criminal complaint against you, and not join any criminal proceedings against you as a civil party;
- bring no civil action against you on account of that research;
- waive, for that research alone, the clauses of its terms of use that would prohibit it;
- confirm the good faith of your approach should an authority or a third party question you about that research.
This commitment does not cover:
- malicious activity;
- actions contrary to the rules above;
- actions contrary to applicable laws;
- testing a node.this installation operated by a customer, without that customer’s consent;
- our providers’ services and other systems outside the scope defined above.
This commitment only covers actions that are TYO DATA’s own to take: it binds neither the judicial authorities nor third parties. This policy is not a general authorisation to test our systems outside the framework it defines.
You remain responsible for complying with the laws and regulations that apply to you, with third-party rights, and with your own obligations regarding personal data protection.
You may also send your report to ANSSI, which forwards it without disclosing your identity (Article L2321-4 of the French Defence Code): cyber.gouv.fr.
Versions of this policy#
We may change this policy at any time and without notice. The version in force is the one published on this page, and it carries its date.
The version applicable to a report is the one in force on the day you sent it. A later change therefore cannot reduce the commitments made to you, nor the rules against which your research is judged.
Governing law#
French law governs this policy.