AussieCyberGuard is committed to maintaining the security of our systems, services, and customer information.
We appreciate the efforts of security researchers, customers, and members of the community who help identify potential security issues. If you believe you have discovered a vulnerability affecting our systems, we encourage you to report it responsibly.
Reporting a Security Issue
If you discover a security vulnerability, please send a report to:
security@aussiecyberguard.au
Please include as much information as possible, including:
- Description of the vulnerability
- Affected system, page, or service
- Steps required to reproduce the issue
- Proof-of-concept details (where appropriate)
- Potential impact
- Your contact information
- Providing detailed information helps us investigate and address issues more efficiently.
What We Ask From Researchers
When conducting security research involving our systems, we ask that you:
- Act in good faith
- Avoid actions that could negatively affect the availability, integrity, or confidentiality of our systems or data
- Do not access, modify, or delete information that does not belong to you
- Do not attempt to access customer information
- Do not perform denial-of-service testing
- Do not conduct social engineering, phishing, physical security testing, or spam campaigns against our personnel, customers, or infrastructure
- Give us reasonable time to investigate and remediate reported issues before publicly disclosing them
What You Can Expect From Us
When a valid vulnerability report is received, we will:
- Acknowledge receipt of the report
- Review and investigate the findings
- Work to validate and remediate confirmed issues
- Communicate with the reporter where appropriate regarding progress and resolution
- We value constructive and responsible security research and appreciate reports that help us improve our security posture.
Scope
This policy applies to systems and services owned and operated by AussieCyberGuard.
Third-party services, platforms, and systems not under our control are outside the scope of this policy and should be reported directly to the relevant provider.
No Bug Bounty Program
AussieCyberGuard does not currently operate a bug bounty or vulnerability reward program.
Submission of a vulnerability report does not create any entitlement to compensation, rewards, or future business opportunities.
Legal Safe Harbor
We will not pursue legal action against individuals who:
- Act in good faith
- Follow this policy
- Avoid causing harm to our systems, customers, or operations
- Promptly report discovered vulnerabilities
- Activities that result in service disruption, unauthorized access to data, privacy violations, or other unlawful actions are not authorized and remain outside the scope of this policy.