Vai al contenuto principale

Vulnerability disclosure

Last updated: 20 September 2026

Toonimo welcomes reports of security vulnerabilities in the Toonimo Digital Adoption Platform, toonimo.com, and related services. This page is the public policy referenced by /.well-known/security.txt (KSI PIY-03).

How to report

Email security@toonimo.com from a mailbox you monitor. Include:

  • A description of the issue and the affected product or URL
  • Steps to reproduce, or a proof of concept that does not include exploit tooling for third-party systems
  • Your assessment of impact
  • Whether you need coordination on disclosure timing

Do not include real customer data, credentials you do not own, or samples of malware. We do not operate a paid bug bounty at this time; we will acknowledge responsible reports.

Scope

  • app.toonimo.com and customer dashboard / editor
  • www.toonimo.com
  • Toonimo Player, APIs, and supporting cloud services operated by Toonimo

Out of scope: third-party applications that Toonimo overlays; denial-of-service tests against production without prior written approval; physical security; social engineering of Toonimo staff or customers.

Our commitment

  • Acknowledge receipt within 3 business days
  • Provide a status update within 10 business days
  • Remediate according to severity (critical/high targeted within 30 days of confirmation)

Encryption

A PGP key for encrypted reports will be published at this anchor when issued. Until then, use the security mailbox over TLS (HTTPS mail providers).

Acknowledgments

We will credit researchers who want to be named after a fix is released, unless the report is invalid or out of scope.