Security and vulnerability disclosure

A clear route for reporting security issues affecting services operated by the .au Domain Observatory.

This policy concerns .auDO-operated services and infrastructure. It does not make .auDO the security contact for third-party domains or organisations that appear in observatory evidence.

Report an issue

Security reports are welcome

Send a concise report to security@domainobservatory.au. Include enough information to understand and reproduce the issue without including unnecessary sensitive data.

Scope

Report issues in .auDO-operated surfaces

In scope

Security issues affecting the public .auDO site, .auDO-operated evidence or status surfaces, access controls protecting gated .auDO routes, and other infrastructure operated specifically for the observatory.

Third-party domains are not in scope

Domains and organisations observed by .auDO remain under their own security and operational control. A visible signal or possible issue relating to a third party should be reported to that organisation through its own published security contact.

Public evidence is not an invitation to test third parties

.auDO publishes bounded observations from public domain-layer signals. Inclusion in the panel, a report or a gated investigation view does not authorise security testing of an observed organisation or its systems.

Useful reports

What to include

A useful report makes the issue easier to verify while minimising unnecessary disclosure.

Describe the affected surface

Include the URL or service, the behaviour you observed and why you believe it creates a security concern.

Provide reproducible steps

Include a minimal sequence, relevant request details and environment information where that helps reproduce the behaviour.

Bound the evidence

Share only the data needed to demonstrate the issue. Do not send unrelated credentials, personal information or third-party data.

Suggest impact cautiously

Describe what you can demonstrate. Avoid assuming access, compromise or impact that has not been observed.

Handling

Assessment, containment and correction

Reports will be assessed against the evidence available and the role of the affected service. Where a material issue is confirmed, .auDO will prioritise proportionate containment or correction and preserve enough information to understand what changed.

Please avoid public disclosure of a suspected issue while it is being assessed where early disclosure would materially increase the risk to the service or its users. This request does not prevent good-faith reporting, independent discussion of already-public information or disclosure required by law.

Related governance

For the wider operating model, see Trust and transparency. Privacy, methodology and use limitations remain separate governance surfaces.