Skip to content
Octopus Core

Responsible disclosure

Octopus Core values the work of security researchers who help keep our website and users safe. This policy explains how to report a security issue to us in good faith and is provided as a draft.

Legal pages are draft content pending review and are not a substitute for professional advice.

Our commitment

We are committed to working with researchers who report vulnerabilities responsibly and in good faith. If you follow this policy, we will treat your report seriously, keep you informed as we investigate, and work to resolve valid issues.

How to report

Please report suspected vulnerabilities to the security contact listed on this website. Send your report privately rather than disclosing it publicly, so we have an opportunity to investigate and remediate first. Where possible, please write in English or Simplified Chinese.

What to include

To help us reproduce and assess the issue quickly, please include clear steps to reproduce, a description of the potential impact, and the affected URL or endpoint. Screenshots or a short proof of concept are helpful where relevant. The more detail you provide, the faster we can respond.

Scope

This policy covers this website and its associated enquiry and assistant endpoints. Other systems, third-party services, and separately governed engagements are outside the scope of this policy. If you are unsure whether something is in scope, please ask before testing.

Rules of engagement

Please act in good faith and avoid harm: do not violate anyone’s privacy, degrade or disrupt our services, or access, modify, or delete data that is not yours. Use only the minimum testing necessary to demonstrate an issue, and stop once you have confirmed it. Give us a reasonable time to investigate and remediate before any public disclosure.

What to expect

We will acknowledge your report, investigate the issue, and work to remediate confirmed vulnerabilities. We may contact you for further information as we assess the report. We do not offer a bug bounty or monetary reward under this policy, and any recognition is at our discretion.

Safe harbour

If you conduct security research in good faith and in accordance with this policy, we will regard that research as authorised and will not pursue action against you for it. This does not authorise activity that breaks the law or harms our users, and it does not waive the rights of third parties. If in doubt about whether your conduct is consistent with this policy, contact us before proceeding.

Legal name:
Octopus Core Pty Ltd
ABN:
28 696 931 236
ACN:
696 931 236
Business location:
Sydney NSW 2007, Australia

Last verified: —