AUSTRAL / Policy

Security

AUSTRAL welcomes clear, good-faith reports that help protect its website, systems and users.

Effective 22 July 2026

Report a vulnerability

Email research@austral.systems with the affected location, impact, reproduction steps and any supporting evidence. Avoid including sensitive data in the initial message.

Research boundaries

Limit testing to AUSTRAL-controlled systems. Do not disrupt services, access data beyond what is necessary to demonstrate the issue, alter or delete data, use social engineering, or test third-party infrastructure.

Coordinated disclosure

Please allow reasonable time for investigation and remediation before publishing details. We will acknowledge useful reports, communicate material progress where practical and coordinate disclosure based on risk.

Scope

This policy covers publicly accessible systems operated by AUSTRAL. It does not authorise activity that is unlawful or outside these boundaries, and it does not apply to third-party services.