Security & vulnerability disclosure
SunLedger holds commercially sensitive information on behalf of Australian solar businesses, and personal information about their customers. We would much rather hear about a security problem from the person who found it than from the person who exploited it.
admin@sunledger.com.au
Put SECURITY in the subject line. English is fine, and a rough report we can reproduce beats a polished one we can't.
What to include
- What the issue is, and the URL or endpoint where it occurs.
- Steps to reproduce — enough that we can see it ourselves.
- What an attacker could actually do with it.
- Any proof of concept, screenshot, or request and response capture.
- How you'd like to be credited, if you'd like to be.
Please don't post the detail publicly or contact our customers directly before we've had a chance to respond.
What we commit to
| Acknowledge your report | 3 business days |
| Tell you our assessment and what we intend to do | 10 business days |
| Keep you updated while it's open | every 14 days |
| Tell you when it's fixed | always |
We're a small business with a lean team, so these are response times we can actually meet rather than the same-day figures a larger organisation would publish. If we're going to be slow, we'll say so rather than go quiet on you.
With your permission we'll name you as the finder when we describe the fix. We don't run a paid bug bounty; if that changes, this page will say so.
Safe harbour
If you make a good-faith effort to follow this policy while researching a vulnerability, we will not pursue or support legal action against you for it. We'll treat your activity as authorised under the Criminal Code Act 1995 (Cth) and other relevant computer-access law so far as it is in our power to do so, and if a third party takes action against you over a report made under this policy, we'll make clear that your research was authorised.
Rules of engagement
To stay within that safe harbour:
- Use only your own account or a test account. SunLedger is multi-tenant, and almost all data in it belongs to someone who did not consent to your testing.
- Stop at proof. Once you've shown access is possible, stop — don't enumerate records, escalate further, or establish persistence.
- Delete anything you obtained once reported, and tell us you have.
- Don't degrade the service — no denial of service, no scanning at a rate that affects real users, no flooding our email or SMS gateways.
- No social engineering or physical intrusion against us, our staff, or our customers.
- Give us reasonable time to fix it before publishing.
Scope
In scope
- sunledger.com.au and www.sunledger.com.au, including the application and its public API
- The customer-facing document pages — proposals, job packs, site plans, progress pages and welcome packs
- Our OAuth integrations, where a flaw in our implementation is involved
Out of scope
- Third-party services we use but don't operate — hosting, database, storage, email and SMS delivery, accounting, aerial imagery, inverter monitoring and rebate trading. Please report those to the vendor.
- Findings needing physical access to a device, or social engineering of staff.
- Automated scanner output with no demonstrated impact — a missing header or a "weak cipher" flag with no exploitation path.
- Denial of service and volumetric testing.
- Best-practice suggestions with no security impact.
Disclosure timing
We ask for 90 days from acknowledgement before public disclosure, and we'll usually be much faster. If we need longer — because a fix requires our customers to act, for instance — we'll explain why and agree a date with you, rather than letting the clock run out in silence. We will not ask you to keep a finding secret indefinitely.
What happens on our side
A report is treated as a potential incident from the moment it arrives. We reproduce it, assess what data is reachable and by whom, check our audit log for evidence it has already happened, fix it, and add an automated check so that class of fault can't return unnoticed. If customer data was reached by anyone other than you, our obligations under the Australian Notifiable Data Breaches scheme apply, and the affected organisations are told first.
Machine-readable version: /.well-known/security.txt