Security Reporting
Report clearly. Minimise sensitive data. Do not exceed your authority.
ASODI accepts written reports about security issues affecting its public product surfaces without granting authority to test or access systems beyond applicable law and explicit permission.
How to report
Send a written report to hq@tvk.group with the subject Security report — ASODI. Include the affected public URL or component, concise reproduction steps, observed impact and the minimum evidence needed to understand the issue.
Data minimisation
Do not send passwords, authentication tokens, private keys, recovery material, classified information or unnecessary personal data. If sensitive evidence is genuinely required, first request an agreed secure exchange route.
Authority boundary
This disclosure page does not grant permission to access accounts, private systems, producer infrastructure or third-party assets; to bypass access controls; to disrupt availability; to exfiltrate data; or to perform destructive, social-engineering or denial-of-service activity. Testing must remain within applicable law and any explicit written authorization you already possess.
Product safety boundary
A reported issue must not be interpreted as evidence that ASODI provides weapon-control, flight-control, spacecraft-actuation or other command authority. The current product boundary remains read-only situational awareness and evidence-preserving inspection.
Boundary
Evidence-led public information.
These public trust pages do not create operational, testing, command or actuation authority and do not substitute for independent certification or review.