TGG/RESPONSIBLE DISCLOSURE

Responsible Disclosure

We value the work of security researchers. If you believe you've found a vulnerability in a system operated by TGG Group, we want to hear from you — directly, and before anyone else.

01How to report

Email dev@tgg.group with the subject line SECURITY. Include steps to reproduce, affected components, and your assessment of impact. Do not include classified information, production credentials, or personal data in the initial report; we will arrange an appropriate secure channel when needed.

02Scope

tgg.group and subdomains operated by TGG Group. Out of scope: denial-of-service testing, social engineering of personnel, physical intrusion, and third-party services we don't operate.

03Our commitments

Acknowledgement within 72 hours. A substantive assessment within 10 business days. Updates until resolution, and credit if you want it — silence if you prefer.

04Safe harbor

We will not pursue legal action against good-faith research that stays within scope, avoids privacy violations and service degradation, and allows reasonable time for remediation before public disclosure.

← SECURITY AT TGG