Skip to content
openaus.org

Security reporting

Report a vulnerability privately.

If you believe openaus.org exposes data, permits unauthorised action or has another security weakness, please report it privately so it can be investigated before public discussion.

Contact

Email security@openaus.org. Include the affected address, observed behaviour, impact, reproducible steps and the minimum evidence needed to understand the issue. Do not send live credentials or personal information in ordinary email.

We aim to acknowledge a credible report within five business days. Resolution time depends on severity and reproducibility. This project does not currently offer a bug bounty or promise payment.

Responsible testing

  • Use only accounts, devices and data you are authorised to use.
  • Do not access, change, retain or disclose another person’s information.
  • Do not disrupt availability, send high-volume traffic, install persistence, use social engineering, or test third-party services outside this project’s control.
  • Stop when you have enough evidence to demonstrate the issue and report it promptly.
  • Allow reasonable time for investigation before disclosure.

Current public boundary

The first public release is read-only. It has no public account, comment, proposal, upload or database interface. Any appearance that those private prototype functions are reachable on the public site should be treated as a security issue.

The machine-readable policy is available at /.well-known/security.txt.

This policy does not authorise unlawful access, privacy invasion, destructive testing or testing of infrastructure owned by another provider.

Policy published 9 October 2026.