Back to Trust & Security

Responsible Disclosure Policy

Version 1.0Effective On publication

Document details

Description
How to report a suspected security vulnerability or concern.
Version
1.0
Effective
On publication
Last reviewed
On publication
Next review
12 months after publication
Owner
Security Lead

Threadline welcomes reports from security researchers and members of the public about suspected vulnerabilities or security concerns affecting our service. This policy explains how to report and what to expect.

1. How to report

Please email support@threadline.com.au using the subject line "Security report", with enough detail for us to reproduce and understand the issue. Do not include personal or health information in an initial report.

2. Please do

  • Report promptly and in good faith
  • Give us reasonable time to investigate and remediate before any public disclosure
  • Avoid accessing, modifying or deleting data that is not yours

3. Please do not

  • Access, download or alter other people’s data
  • Degrade, disrupt or test the availability of the service (for example, denial-of-service testing)
  • Use social engineering, phishing or physical attacks against our staff or facilities

4. What to expect

We will acknowledge your report, investigate, and keep you informed of the outcome where appropriate. We will not pursue legal action against researchers who act in good faith and comply with this policy.