TGG/RESPONSIBLE DISCLOSURE
Responsible Disclosure
We value the work of security researchers. If you believe you've found a vulnerability in a system operated by TGG Group, we want to hear from you — directly, and before anyone else.
01How to report
Email dev@tgg.group with the subject line SECURITY. Include steps to reproduce, affected components, and your assessment of impact. Do not include classified information, production credentials, or personal data in the initial report; we will arrange an appropriate secure channel when needed.
02Scope
tgg.group and subdomains operated by TGG Group. Out of scope: denial-of-service testing, social engineering of personnel, physical intrusion, and third-party services we don't operate.
03Our commitments
Acknowledgement within 72 hours. A substantive assessment within 10 business days. Updates until resolution, and credit if you want it — silence if you prefer.
04Safe harbor
We will not pursue legal action against good-faith research that stays within scope, avoids privacy violations and service degradation, and allows reasonable time for remediation before public disclosure.