Website Security Policy
How we protect this site, and how to tell us if you find a problem.
Security Practices
We take reasonable, industry-standard steps to keep this website and your data secure:
- All traffic is encrypted in transit via HTTPS.
- Hosting and DDoS protection through Cloudflare.
- Access-controlled database storage via MongoDB Atlas.
- Session-based, time-limited admin authentication.
No website can guarantee complete security. We continually review and improve our practices, but no system is entirely risk-free.
Responsible Disclosure
If you're a security researcher and discover a vulnerability on tmfengineering.com, we ask that you disclose it responsibly: give us reasonable time to investigate and fix the issue before sharing it publicly, and avoid accessing, modifying, or deleting data beyond what's needed to demonstrate the issue.
Reporting Vulnerabilities
To report a security issue, email us directly rather than using the public contact form:
Please include steps to reproduce the issue and its potential impact. We'll acknowledge genuine reports promptly and keep you updated as we work on a fix.
