This document forms part of the Ozibus Public Website Legal Centre. It should be read together with other policies that apply to the services and channels you use.
Ozibus welcomes responsible reports concerning potential security vulnerabilities.
Researchers should:
- avoid accessing information that does not belong to them;
- avoid disrupting production systems;
- avoid social engineering;
- avoid denial-of-service activity;
- minimise collection of personal information; and
- report vulnerabilities promptly and confidentially.
Security reports should be sent to:
Ozibus will acknowledge legitimate reports, investigate them and coordinate remediation where appropriate.
Submitting a report does not create an entitlement to payment unless Ozibus has expressly established a bounty program.
Ozibus does not authorise testing that breaches applicable law or causes harm to users, customers or infrastructure.