Report a vulnerability.
Version 1.0 · Effective 6 August 2026
Send suspected security vulnerabilities to security@tische.com.au. Include the affected URL or component, reproducible steps, impact and supporting evidence. Do not include real guest data beyond the minimum needed to identify the issue.
Good-faith research
We welcome research designed to improve Tische’s security. Keep testing to accounts and data you own or have explicit permission to use. Stop if testing could affect service availability, other users, production data or privacy, and report the issue promptly.
Out of bounds
- Social engineering, phishing, credential attacks or physical attacks.
- Denial of service, traffic flooding, destructive testing or automated scanning that materially affects the service.
- Accessing, changing, downloading or retaining another person’s data.
- Privacy violations, extortion, public disclosure before remediation, or breaching applicable law.
- Testing third-party providers outside Tische’s control without their permission.
What Tische will do
We aim to acknowledge a complete report within five business days, investigate proportionately, keep the reporter informed of material progress and coordinate a reasonable disclosure timeline. Response and remediation times depend on severity and complexity. This is not currently a paid bug-bounty programme, and no reward is promised.
Safe-harbour intent
If research is conducted in good faith and follows this policy, Tische does not intend to pursue legal action solely for that authorised research. This statement cannot authorise conduct prohibited by law or by third-party systems.