Trust and security
Security Policy
Tech Team Lead follows risk-based security practices for authentication, authorization, validation, logging, infrastructure and operational access.
Last updated: 11 July 2026
Security practices
- Server-side authorization and ownership checks
- Secure session cookies and controlled session expiry
- Rate limiting and abuse protection
- Input and file validation
- Audit logging for sensitive administrative actions
- HTTPS, secure database connections and private object storage
Credentials and secrets
Passwords, database URLs, API keys, SMTP passwords and private access tokens must not appear in public pages, repositories, screenshots or analytics systems.
Responsible disclosure
If you believe you found a security issue, contact Tech Team Lead privately with the affected URL, reproduction steps and potential impact. Do not access unnecessary data, disrupt services or publicly disclose the issue before it is reviewed.
No unverified compliance claims
The website must not claim certifications, formal partnerships or compliance status without valid evidence and an accurate scope statement.
Questions about this policy can be submitted through the Contact page.