TSHQ.TECH · THE PAPERWORK, IN THE OPEN
TRUST · RESPONSIBLE DISCLOSURE

Found something? We want to hear from you.

We build security-first software, and we know that careful outsiders find things insiders miss. If you believe you've found a vulnerability in this website or any Technology Solutions HQ product, thank you — this page is our promise about what happens next.

How to report

Email security@tshq.tech with enough detail for us to reproduce the issue: what you found, where, and the steps you took. Our machine-readable contact details live at /.well-known/security.txt. If the finding is sensitive, say so and we can arrange a safer channel before you share specifics.

What we promise

We will acknowledge your report within five working days, usually sooner — we are a small studio and the person reading your email is the person who fixes things. We will keep you informed as we investigate, tell you when the issue is resolved, and credit you publicly if you would like credit (or preserve your anonymity if you'd rather). We will not take legal action against good-faith security research conducted within the spirit of this policy, and we regard people who report responsibly as allies, not adversaries.

What we ask

Act in good faith: don't access, alter or retain data that isn't yours beyond the minimum needed to demonstrate the issue; don't degrade the service for others (no denial-of-service testing); don't use social engineering, phishing or physical attacks; and give us reasonable time to fix an issue before disclosing it publicly. In return we will move quickly and treat you well.

Scope

This policy covers tshq.tech and its subdomains, our redirect domains, and Technology Solutions HQ products as they launch. Infrastructure belonging to our providers (such as Microsoft Azure or GitHub) is governed by their own programmes.

TECHNOLOGY SOLUTIONS HQ LIMITED · COMPANY NO. 9444797 · NZBN 9429053815910 · AOTEAROA NEW ZEALAND
LAST UPDATED 22 JULY 2026 · SECURITY.TXT EXPIRES 31 JULY 2027