Describe the affected surface
Include the URL or service, the behaviour you observed and why you believe it creates a security concern.
A clear route for reporting security issues affecting services operated by the .au Domain Observatory.
This policy concerns .auDO-operated services and infrastructure. It does not make .auDO the security contact for third-party domains or organisations that appear in observatory evidence.
Report an issue
Send a concise report to security@domainobservatory.au. Include enough information to understand and reproduce the issue without including unnecessary sensitive data.
Scope
Security issues affecting the public .auDO site, .auDO-operated evidence or status surfaces, access controls protecting gated .auDO routes, and other infrastructure operated specifically for the observatory.
Domains and organisations observed by .auDO remain under their own security and operational control. A visible signal or possible issue relating to a third party should be reported to that organisation through its own published security contact.
.auDO publishes bounded observations from public domain-layer signals. Inclusion in the panel, a report or a gated investigation view does not authorise security testing of an observed organisation or its systems.
Useful reports
A useful report makes the issue easier to verify while minimising unnecessary disclosure.
Include the URL or service, the behaviour you observed and why you believe it creates a security concern.
Include a minimal sequence, relevant request details and environment information where that helps reproduce the behaviour.
Share only the data needed to demonstrate the issue. Do not send unrelated credentials, personal information or third-party data.
Describe what you can demonstrate. Avoid assuming access, compromise or impact that has not been observed.
Handling
Reports will be assessed against the evidence available and the role of the affected service. Where a material issue is confirmed, .auDO will prioritise proportionate containment or correction and preserve enough information to understand what changed.
Please avoid public disclosure of a suspected issue while it is being assessed where early disclosure would materially increase the risk to the service or its users. This request does not prevent good-faith reporting, independent discussion of already-public information or disclosure required by law.
Related governance
For the wider operating model, see Trust and transparency. Privacy, methodology and use limitations remain separate governance surfaces.