# Yoursoftware Pty Ltd — Coordinated Vulnerability Disclosure (CVD) # Per RFC 9116. Drop at /.well-known/security.txt on every public domain # (yoursoftware.com.au and all sub-domains). Contact: mailto:security@yoursoftware.com.au Contact: https://yoursoftware.com.au/security Expires: 2027-05-16T00:00:00Z Preferred-Languages: en, en-AU Canonical: https://yoursoftware.com.au/.well-known/security.txt Policy: https://yoursoftware.com.au/security#disclosure Acknowledgments: https://yoursoftware.com.au/security#thanks # We commit to: # - Acknowledging your report within 5 business days # - Triaging within 10 business days # - Coordinating responsible disclosure # - Crediting researchers who follow our policy (unless you prefer anonymity) # # We ask you to: # - Not access, modify, or exfiltrate customer data # - Not run automated scans against production beyond rate limits # - Not run DoS / DDoS / brute-force / spam tests # - Test only on accounts you own or have explicit permission to test # - Give us a reasonable disclosure window before publishing # # Out of scope (please do not report): # - Email security best-practice advice without a working exploit (SPF/DKIM/DMARC nuances we already know about) # - Outdated TLS cipher reports without a working downgrade # - Reports from automated scanners without a working PoC # - Social engineering against staff or family members # - Physical attacks against offices # # Safe Harbor: # Activity in good faith and compliant with this policy is authorised and we will # not pursue civil or criminal action. The Computer Misuse Act / Privacy Act / etc. # apply for activity outside this policy.