Security & Responsible Disclosure
รายงานช่องโหว่ที่ security@tiitrust.com พร้อม URL ขั้นตอนทำซ้ำ ผลกระทบ และหลักฐานที่ไม่เปิดเผยข้อมูลบุคคลอื่น ทีมงานควรตอบรับหมายเลขอ้างอิงและกำหนด SLA ตามความรุนแรงก่อน Production
ขอบเขตมาตรการขั้นต่ำ
- MFA สำหรับ Admin และบัญชีสิทธิสูง, RBAC/least privilege และ periodic access review
- Hosted payment fields; TII ไม่เก็บเลขบัตรเต็มหรือ CVV
- Signed webhooks, idempotency key, replay protection และ append-only audit events
- Encryption in transit/at rest, secrets management, backup และ restore test
- CSP, HSTS, Permissions-Policy, rate limit, bot protection และ dependency scanning
- Incident response, evidence preservation, notification assessment และ post-incident review
ห้ามทดสอบด้วยการทำลายข้อมูล เข้าถึงข้อมูลผู้อื่น Social Engineering หรือรบกวนบริการ
กลับ Trust & Legal