Last updated: 17 August 2026

Scope of this page

This page describes the security posture of this website only, www.tsgtechnology.com.au, published by TSG Technology Pty Ltd (ACN 697 960 786) ("TSG Technology", "we", "us" or "our").

The platforms we build and operate for clients are governed separately, under the security, control and assurance obligations agreed with each client and, where applicable, with the licensee or institution operating the platform. Nothing on this page describes those environments. If you are assessing a TSG Technology platform, contact us and we will provide the relevant documentation directly.

How this site is built

This is a static website. It is a set of pre-built HTML, CSS, image and script files served from object storage through a content delivery network. There is no application server, no server-side code execution and no database behind it.

That architecture is the substance of the security position here. Most classes of web vulnerability, including injection into a backend database, authentication bypass and server-side request forgery, have no surface to attack because the corresponding components do not exist.

What this site does not hold

  • No user accounts, logins, passwords or sessions.
  • No forms, so nothing you type is submitted to or stored by us.
  • No payment, credit or banking data.
  • No client financial data or personal financial records.
  • No analytics, advertising or tracking tools.

The only information associated with your visit is standard technical request data recorded by our delivery and security providers, as described in our Privacy Policy.

Transport and delivery

All traffic is served over HTTPS, negotiating TLS 1.3 with authenticated encryption. Plain HTTP requests are permanently redirected to HTTPS. The site is delivered through a content delivery and security network that provides TLS termination, edge caching and denial of service protection, in front of origin storage hosted in Australia, in the Amazon Web Services Sydney region (ap-southeast-2).

Content integrity

The site is deployed from version control through an automated pipeline. Every change is committed, reviewed in history and deployed by that pipeline rather than edited in place, so the content served can always be traced back to a specific change. Publishing credentials are held as protected secrets and are not present in the site or its source.

Reporting a vulnerability

If you believe you have found a security issue in this website, please tell us at [email protected]. Include enough detail to reproduce the issue, and give us a reasonable opportunity to investigate and respond before disclosing it publicly.

We ask that you do not run automated scanning that degrades the site for other visitors, do not attempt to access or modify data that is not yours, and do not use social engineering against our people. We do not operate a paid bug bounty, but we will acknowledge your report and we are glad to credit you once an issue is resolved.