# Responsible Disclosure Policy
At Ausacorp, we take security seriously and value the contributions of security researchers who help us identify and responsibly disclose vulnerabilities.
If you discover a security issue in our systems, we encourage you to report it so we can investigate and remediate it promptly.
—
## ๐ฌ Reporting a Vulnerability
Please report vulnerabilities to:
security@ausacorp.com
To help us triage efficiently, include:
* A clear description of the issue
* Steps to reproduce (proof of concept preferred)
* Affected asset(s) (URL, IP, service)
* Any relevant logs, screenshots, or payloads
* Potential impact assessment
We support encrypted communication. You may use our PGP key:
https://www.ausacorp.com/pgp-key.txt
—
## ๐ Scope
In scope:
* Ausacorp-owned domains and subdomains
* Public-facing services operated by Ausacorp
Out of scope:
* Third-party services or platforms not owned by Ausacorp
* Denial of service (DoS/DDoS) testing
* Physical or social engineering attacks
If you are unsure whether a target is in scope, please contact us before testing.
—
## โ๏ธ Safe Harbor
We will not pursue legal action against researchers who:
* Act in good faith
* Avoid violating privacy or accessing unrelated data
* Do not disrupt services or degrade performance
* Provide us reasonable time to remediate before public disclosure
—
## ๐ค What You Can Expect from Us
* Acknowledgement within **5 business days**
* Ongoing communication during investigation
* Notification when the issue is resolved
Where appropriate, we will publicly acknowledge researchers who are first to report a valid vulnerability (unless anonymity is requested).
—
## ๐งช Testing Guidelines
You agree to:
* Only test systems you have permission to access
* Avoid data exfiltration, modification, or destruction
* Limit testing to the minimum necessary to demonstrate the issue
* Immediately report any exposure of sensitive data
—
## โ ๏ธ Testing Authorization
You do **not** need prior approval for low-impact, non-disruptive testing conducted in good faith.
However, you **must contact us before proceeding** with any testing that could:
* Impact service availability or performance
* Generate significant traffic or automated scanning activity
* Involve brute force, rate testing, or resource exhaustion
* Affect other users or data
If in doubt, contact us first at
security@ausacorp.com
—
## ๐ซ Out of Scope Findings
The following are generally not prioritized:
* Missing or misconfigured security headers without exploitability
* SPF, DKIM, or DMARC issues without demonstrable impact
* Clickjacking on non-sensitive pages
* Version disclosures without a working exploit
* Rate-limiting issues without abuse impact
* Publicly accessible files intended for public use
—
## ๐ง Final Notes
We believe in collaborative security. Responsible disclosure helps protect both our systems and our users.
Ausacorp reserves the right to update this policy at any time.
_Last updated: April 13, 2026_