Vulnerability Disclosure Policy and Program

Helping us maintain secure online services through responsible vulnerability reporting

Our Commitment to Security

Career Money Life maintains a Vulnerability Disclosure Policy and Program to give security researchers a clear point of contact for reporting potential security vulnerabilities.

Responsible Reporting

Responsible Reporting

We encourage the responsible disclosure of security vulnerabilities as soon as possible.

Transparency & Respect

Transparency & Respect

All good-faith efforts to help make our websites more secure are greatly appreciated.

No Compensation

No Compensation

We do not offer compensation or public credit for vulnerability disclosures.

Scope of Security Research

To ensure responsible disclosure, the following guidelines outline what is considered in scope and out of scope under this policy.

Security research within scope

Security research within scope

This policy is limited to Career Money Life online services to which you have lawful access.

Security research out of scope

Security research out of scope

  • Physical attacks or tests against Career Money Life, its employees or property belonging to Career Money Life or its staff
  • Social engineering or phishing
  • Clickjacking
  • Denial of service or brute force testing
  • Weak or insecure TLS/SSL ciphers or certificates
  • Misconfigured DNS records (including for example SPF and DMARC)
  • Attempts to modify, exfiltrate or destroy data
  • Access or attempt to access accounts or data that do not belong to you
  • Use of automated vulnerability assessment tools
  • Submitting false or dangerous information or data on the Career Money Life websites, including malware
  • Actions that violate Australian law.

How to report a vulnerability

Please complete the form on this page, with enough detail that we can replicate the issue. If we require additional information, we may contact you using the details you provide on the form.

When you choose to share your contact details with us, we will:

  • Respond to you within five business days, acknowledging that your report has been received.
  • To the best of our ability, we will confirm the existence of the vulnerability.
  • Maintain an open dialogue to discuss issues on our progress and be as transparent as possible about the remediation process.