Skip to content
THOS

Built and operated by Laetoli (T) Limited in Dar es Salaam. A private system, built to national standards.

Language

Disclosure policy

If you find a security defect in THOS, write to support@laetoli.tz. Tell us what you found and how to reproduce it.

Do not access, alter or retain another person’s health record. If a defect exposes one, stop there and say so in the report rather than demonstrating its extent.

What you can expect

Acknowledgement
Five working days
Assessment
Thirty days
Time before you publish
Ninety days
Credit
Yes, unless you decline
A bounty
NoneThis is a private company building a system no ministry has adopted and that serves no patients yet.

What has been tested

And what has not

Row-level security
On every clinical tableIt is the authorisation boundary, not the client. Tested by executing the attack as the attacker’s role, not by reading the policy.
Column grants
Enumerated and checkedA policy decides which row; a grant decides which column. Not looking at grants is how an account could promote itself, a defect closed in August 2026.
Two-factor authentication
Required for the operatorThe operator console requires aal2. For everybody else it is offered and not required.
Independent penetration test
Never performedNobody outside has ever attacked this system. Every defect found so far was found by the people who wrote it.
Sign-in throttling
Not configuredThere is no application-level limit on sign-in attempts. It is the largest open gap.

What is in scope

tibaecosystem.co.tz and its subdomains, the clinical application, and the database behind them. Out of scope: the third-party services we run on, which have their own disclosure policies.