Security & vulnerability disclosure

SunLedger holds commercially sensitive information on behalf of Australian solar businesses, and personal information about their customers. We would much rather hear about a security problem from the person who found it than from the person who exploited it.

admin@sunledger.com.au

Put SECURITY in the subject line. English is fine, and a rough report we can reproduce beats a polished one we can't.

What to include

  1. What the issue is, and the URL or endpoint where it occurs.
  2. Steps to reproduce — enough that we can see it ourselves.
  3. What an attacker could actually do with it.
  4. Any proof of concept, screenshot, or request and response capture.
  5. How you'd like to be credited, if you'd like to be.

Please don't post the detail publicly or contact our customers directly before we've had a chance to respond.

What we commit to

Acknowledge your report3 business days
Tell you our assessment and what we intend to do10 business days
Keep you updated while it's openevery 14 days
Tell you when it's fixedalways

We're a small business with a lean team, so these are response times we can actually meet rather than the same-day figures a larger organisation would publish. If we're going to be slow, we'll say so rather than go quiet on you.

With your permission we'll name you as the finder when we describe the fix. We don't run a paid bug bounty; if that changes, this page will say so.

Safe harbour

If you make a good-faith effort to follow this policy while researching a vulnerability, we will not pursue or support legal action against you for it. We'll treat your activity as authorised under the Criminal Code Act 1995 (Cth) and other relevant computer-access law so far as it is in our power to do so, and if a third party takes action against you over a report made under this policy, we'll make clear that your research was authorised.

Rules of engagement

To stay within that safe harbour:

Scope

In scope

Out of scope

Disclosure timing

We ask for 90 days from acknowledgement before public disclosure, and we'll usually be much faster. If we need longer — because a fix requires our customers to act, for instance — we'll explain why and agree a date with you, rather than letting the clock run out in silence. We will not ask you to keep a finding secret indefinitely.

What happens on our side

A report is treated as a potential incident from the moment it arrives. We reproduce it, assess what data is reachable and by whom, check our audit log for evidence it has already happened, fix it, and add an automated check so that class of fault can't return unnoticed. If customer data was reached by anyone other than you, our obligations under the Australian Notifiable Data Breaches scheme apply, and the affected organisations are told first.

Machine-readable version: /.well-known/security.txt