VULNERABILITY DISCLOSURE
Report security issues here
Peji iri riri muEnglish.
Found something? Email privacy@t3ratech.co.zw with subject SECURITY — include what you found, how to reproduce it, and impact. We reply within 7 days.
Safe harbor
Good-faith security research is welcome: report privately, give us reasonable time to fix (we aim for 90 days), don't access or modify others' data, don't degrade the service. We will not pursue legal action against research that follows this.
In scope
- The site, API, and MCP surface at market-pulse.t3ratech.co.zw
- Authentication, keys, claims, reports, and evidence integrity
- Anything that lets someone forge evidence, ownership, or grades
Out of scope
- Third-party sites and services linked from the directory
- Self-XSS, missing security headers that can't be exploited, theoretical issues without a working proof
Our own posture
SHA-256-hashed API keys, HMAC sessions, read-only public surface, append-only evidence, no credential storage, no CAPTCHA/KYC bypass, CSP + nosniff + referrer policy on every response.
19 September 2026 · TeraTech Solutions (Private) Limited · t3ratech.co.zw