Found a problem? Tell us.
We sell security advice, so we had better be willing to take it. If you have found a vulnerability in something of ours, we want to hear about it.
How to report
Email connect@summitcybergroup.com.auwith enough detail for us to reproduce it. Proof-of-concept code, affected URLs and a description of the impact all help. Write in English.
If the report contains anything sensitive, say so and we will arrange an encrypted channel before you send it. Do not include real customer data in a report.
What we will do
- Acknowledge within two business days. We are a small team in Perth (AWST), so allow for the time zone
- Tell you what we found when we have assessed it, including if we disagree that it is a vulnerability, and why
- Keep you updated while we fix it, rather than going quiet
- Credit you if you would like to be credited, once it is resolved
We do not operate a paid bug bounty. We will not pretend otherwise to attract reports.
In scope
summitcybergroup.com.auand its subdomainssummitcyber.com.au- Any service we publish at those domains
Out of scope
Our customers' systems are not ours to authorise testing against. If you believe you have found something affecting a Summit customer, report it to us and we will route it — do not test it.
- Denial of service, load testing, or anything that degrades availability
- Social engineering of our staff, customers or suppliers
- Physical attacks against our offices or hardware
- Reports generated by an automated scanner with no demonstrated impact
- Missing security headers or best-practice findings with no exploitable consequence
- Third-party services we consume but do not control — report those to their owners
Safe harbour
If you act in good faith, stay within the scope above, avoid privacy violations and service disruption, and give us a reasonable chance to fix the issue before you discuss it publicly, we will not pursue or support legal action against you for your research.
This commitment is ours to give and covers only Summit Cyber Group. It cannot authorise you to test systems belonging to anyone else, including our customers.
Machine-readable contact details are published at/.well-known/security.txt.