Security
Last updated: July 25, 2026
1. Our Security Commitment
The security of the tira.ro website and the protection of information submitted through it are important priorities.
Reasonable technical and organisational measures are considered and applied to reduce the risks of unauthorised access, loss, alteration, disclosure, or improper use of information.
Security measures are assessed and adapted according to the nature of the website, the data being processed, the technical solutions used, and the risks identified.
However, no online platform, transmission method, or electronic storage solution can guarantee absolute security.
2. Scope
This page describes the general principles followed to protect:
- the website and its associated technical infrastructure;
- information submitted through the contact form;
- technical data generated when the website is accessed;
- administrative accounts and tools used to manage the website;
- the availability and integrity of published content.
The information provided is general and does not constitute a complete description of the technical configuration, internal mechanisms, or security procedures in use.
3. Protection of Communications
Where available and properly configured, the website uses a secure HTTPS connection to protect information transmitted between the user’s browser and the server.
Users are encouraged to check for a secure connection in the browser’s address bar before submitting information through the website.
HTTPS helps protect communications in transit, but it does not eliminate all risks associated with internet use or the security of the user’s device.
4. Protection of the Technical Infrastructure
Measures used to manage and protect the website may include:
- hosting and technical infrastructure services provided by specialised operators;
- server-level and application-level protection mechanisms;
- restricted access to administrative areas;
- monitoring of errors and unusual activity;
- protection against abusive automated access, unsolicited messages, and attempted attacks;
- the creation of backups, where necessary and available.
The actual implementation of these measures may depend on hosting providers, installed technical components, and the website’s configuration.
5. Updates and Maintenance
The website platform, theme, extensions, and other technical components may be updated periodically to address vulnerabilities, maintain compatibility, and improve operation.
Components that are no longer required may be disabled or removed in order to reduce the attack surface.
In certain circumstances, the website may be temporarily unavailable during maintenance, updating, remediation, or technical verification activities.
6. Access Control
Access to the website’s administrative functions and technical resources is intended solely for authorised persons.
Measures may include:
- individual authentication credentials;
- strong passwords that are updated where necessary;
- multi-factor authentication, where available;
- limiting access rights according to responsibilities;
- revoking access when it is no longer required;
- monitoring repeated or unusual authentication attempts.
Details concerning specific authentication and access-control mechanisms are not made public, in order to avoid reducing the effectiveness of the protective measures.
7. Protecting Submitted Data
Data submitted through the contact form is used to manage requests and is accessible only to the extent required for that purpose.
Users are asked not to submit through the website:
- passwords or authentication codes;
- complete banking or payment-card details;
- copies of identity documents;
- medical information or other special categories of personal data;
- confidential information that is not necessary for the request;
- personal data belonging to other individuals without an appropriate legal basis.
Further information about the collection and use of data is available in the Privacy and Cookie Policy.
8. Providers and External Services
Third-party services may be used for hosting, administration, analytics, technical protection, or the provision of certain website functions.
These providers manage their own systems and apply their own security policies, measures, and procedures.
Appropriate services are selected according to the nature of the website, but the website owner cannot exercise absolute control over infrastructure or systems independently managed by third-party providers.
9. Backups and Continuity
Where necessary and technically possible, backups of the website’s content and configuration may be created.
These backups may be used to restore the website following errors, failures, security incidents, or accidental data loss.
The existence of backups does not guarantee the complete or immediate recovery of all information and functionality.
10. Monitoring and Incident Management
Relevant technical events, error messages, attempted unauthorised access, and other activity that may indicate a security issue may be monitored.
If an incident is identified, measures may include:
- temporarily restricting or suspending access;
- isolating affected components;
- updating or replacing vulnerable components;
- resetting access credentials;
- restoring a backup;
- informing technical providers or competent authorities where necessary;
- informing affected individuals where required by applicable law.
11. User Responsibility
Website security also depends on how the website is used.
Users are advised:
- to use updated devices and browsers;
- to avoid accessing the website through insecure networks;
- to verify the website address before submitting information;
- not to follow suspicious links claiming to represent tira.ro;
- not to submit sensitive information through the contact form;
- to use appropriate security solutions on their own devices.
The website owner cannot control and is not responsible for the security of a visitor’s device, connection, browser, or accounts.
12. Fraudulent Messages and Requests
The tira.ro website will not request passwords, authentication codes, complete payment-card details, or the installation of unknown applications through its public pages.
Users are encouraged to treat with caution any messages, links, or requests claiming to originate from this website but using unusual addresses, domains, or communication methods.
Where there is any doubt, the authenticity of a message may be checked using the details available on the Contact page.
13. Reporting a Vulnerability
If you identify a potential vulnerability or security issue associated with the tira.ro website, please report it through the Contact page.
Where possible, the report should include:
- the affected page or functionality;
- a clear description of the issue observed;
- the steps required to reproduce the issue;
- the approximate date and time when it was identified;
- screenshots or other relevant information, without including unnecessary personal data.
Please do not exploit the vulnerability, access, alter, download, or disclose data that does not belong to you, or perform actions that may affect the availability of the website.
14. Responsible Disclosure
Individuals who report a potential security issue in good faith are asked to allow reasonable time for the issue to be reviewed and addressed before making the information public.
Reporting a vulnerability does not automatically create a right to payment, a reward, public recognition, or a professional engagement.
Unauthorised testing, exploitation of vulnerabilities, access to other individuals’ data, or disruption of the website’s operation is prohibited.
15. Limitations
Although reasonable measures are followed to protect the website, it cannot be guaranteed that:
- the website will always be available and free from errors;
- every attempted attack will be prevented;
- every vulnerability will be identified immediately;
- the transmission of information over the internet will be entirely risk-free;
- services provided by third parties will operate without interruption or security incidents.
The website should be used with an understanding of the ordinary risks associated with the online environment.
16. Updates to This Security Page
This page may be updated periodically to reflect technical, operational, legal, or security-related changes affecting the website.
The updated version will be published on this page together with the date of the latest revision.
17. Contact
To report a vulnerability, incident, or concern regarding the security of the website, you may contact us through the Contact page.
To assist with the review of your report, please include a clear description and sufficient technical information, without submitting unnecessary personal or confidential data.