Security Policy

Protecting users, products, and infrastructure is part of how we build and operate.

Report a security issue

If you find a potential security issue in a TacticSpace website or product, send complete reproduction steps, the expected impact, and only the screenshots needed to investigate. Please do not disclose vulnerability details before a fix is available.

contact@tacticspacetech.com

Our security principles

  • • Least privilege: production access, automation, and service accounts receive only the permissions needed for their task.
  • • Secret isolation: credentials are stored in managed secret systems and kept out of source code and build logs.
  • • Defense in depth: encrypted transport, security headers, dependency auditing, and isolated ephemeral CI runners.
  • • Data minimization: we collect and retain only what is needed to provide features, protect the service, and deliver support.

Responsible security research

Avoid accessing other users’ data, degrading availability, social engineering, or broad automated scanning. We will prioritize collaboration with researchers acting in good faith, within the law, and with care to minimize impact.

Response target

We aim to acknowledge reports within three business days and provide updates as validation and remediation progress, based on severity.

Last updated: September 4, 2026