#01Purpose and legal status
ACADEMYSHIP PTY LTD (ACN 698 283 448, ABN 89 698 283 448) ("Academyship") welcomes reports of genuine security vulnerabilities in our production systems. This page describes how to report a vulnerability to us and how we practise coordinated vulnerability disclosure.
This policy is not authorisation to perform unrestricted security testing against Academyship or its customers, and it is not a bug-bounty offer. It sets out the narrow conditions under which we will treat good-faith, in-scope research as welcome. Testing outside these conditions is not authorised.
#02What to report
Please report vulnerabilities you find in an in-scope Academyship-owned public system. Examples of issues we want to hear about include:
- authentication or session-management bypass;
- failures of tenant isolation (access to another Institution's data);
- broken access control or privilege escalation;
- injection vulnerabilities (for example, SQL or command injection);
- exposed secrets, credentials or keys;
- unauthorised file access or path traversal;
- serious security misconfiguration or unintended exposure of personal data;
- a credential-verification page, link or code that reveals more than the limited credential details it is meant to show, or that could be guessed or enumerated; and
- a weakness in a payment, wallet, mandate, refund or electronic-signing workflow that could allow an unauthorised transaction or signature, or a change to signing evidence.
Report issues like the last two from what you notice in ordinary use or passive observation. Do not test them against live records, transactions or signing requests (see sections 3 and 5).
#03In-scope systems
In-scope systems are Academyship-owned public systems expressly covered by this policy or prior written testing approval. Do not treat a domain name, IP address, API endpoint or asset as in scope merely because it appears connected to Academyship. If Academyship has not expressly covered a system, request scope confirmation from security@academyship.com.au before testing.
Without Academyship's prior written authorisation, the only security research permitted is passive, non-invasive observation of Academyship's public, unauthenticated web pages at academyship.com.au, carried out within the rules in section 5. Passive, non-invasive observation means looking at those pages, and at what they ordinarily deliver to any visitor's browser (such as page content, scripts, response headers and certificate details), using a browser or a small number of ordinary requests. It does not include automated or high-volume scanning, fuzzing, sending attack or injection payloads, submitting forms with test payloads, attempting to sign in, creating accounts or trying to bypass any control.
Any other testing requires Academyship's prior written authorisation and must stay within the scope and conditions Academyship sets. This includes testing of:
- any authenticated service, portal, account or Institution tenant, and any test environment;
- any payment, wallet, PayTo, top-up or refund function;
- any electronic-signing workflow or signing evidence; and
- any credential-verification page, endpoint, link or code.
Public credential-verification pages are reportable (section 2), but they show real people's credential details, so they must not be tested against live data. You may view a credential using a link or code you legitimately received. Do not alter, guess, generate, enumerate or replay verification links, codes or tokens.
#04Out-of-scope findings
The following are generally not treated as reportable vulnerabilities unless you can demonstrate a real, exploitable security impact:
- missing low-risk HTTP headers or best-practice suggestions without a demonstrated exploit;
- self-XSS that cannot affect another user;
- rate-limiting observations without demonstrated impact;
- clickjacking on pages with no sensitive action;
- automated scanner output without a validated finding;
- social engineering, phishing or physical attacks;
- denial-of-service or resource-exhaustion testing;
- spam or content-injection without security impact; and
- issues in third-party services or already-public information.
The following are expressly out of scope unless Academyship gives prior written permission: real Institution tenants; real student or staff accounts; Customer Data; authenticated production testing; leaked credentials; Customer-selected integrations; third-party provider systems; high-volume account creation; denial-of-service testing; live payment, wallet, mandate or refund transactions; live signing requests and signing evidence; and credential-verification endpoints, links and codes.
#05Rules for good-faith research
To keep research safe for users and lawful, you must:
- stop as soon as you can demonstrate a vulnerability and before you access, download or view Customer Data or personal information beyond the minimum needed to prove the issue;
- not exfiltrate, alter, delete, encrypt or destroy any data;
- not disrupt or degrade the Services, and not perform denial-of-service or high-volume automated scanning;
- not attempt credential attacks, phishing, or social engineering of staff, customers or users;
- not attempt to access another tenant's data, and not use access to one tenant, account or role to reach another (tenant pivoting);
- not enumerate, guess, generate, alter or replay credential-verification, invitation, signing or other access links, codes or tokens;
- not start, change, approve, reverse or refund a live payment, top-up, mandate or wallet transaction, and not create, alter, sign or decline a live signing request or change its evidence;
- not bypass a clear warning, paywall or authorisation boundary beyond what is necessary to demonstrate the issue; and
- use only test accounts and data you are entitled to use, and use the minimum proof necessary.
You must obtain Academyship's prior written authorisation, by contacting security@academyship.com.au, before any testing beyond the passive observation described in section 3, including authenticated, tenant, payment, signing or credential-verification testing. Use an Academyship-provided test account or environment where one is available; do not substitute a real customer tenant, real student or staff account, or leaked credential.
#06Safe-harbour position
Academyship does not intend to initiate legal action solely for research that strictly complies with this policy. Academyship cannot authorise activity against third parties or waive the rights of Customers, providers, regulators, law-enforcement bodies or other parties.
You remain responsible for complying with applicable law. This policy does not promise that Academyship will defend, indemnify or represent a researcher in any action by a third party, and it is not a grant of immunity from liability.
#07How to report
Send your report to security@academyship.com.au. This is Academyship's monitored reporting channel. To help us assess it quickly, please include:
- a clear description of the vulnerability and its potential impact;
- the affected URL, endpoint or component;
- step-by-step, reproducible instructions or a minimal proof of concept;
- any prerequisites (for example, a required role);
- your contact details and preferred language for correspondence; and
- whether you intend to disclose publicly, and any timeline you have in mind.
Please report one issue per message where practical. We accept reports in English.
#08Handling sensitive evidence
Send only the minimum evidence needed to show the issue. Redact, or replace with placeholders, any personal information, passwords, credentials, secrets, payment details and access links or tokens (including verification, invitation and signing links). Do not send copies of Customer Data, identity documents, tax file numbers, Unique Student Identifiers, bank or card details, or other people's signed documents or credentials. Never email suspected illegal material. If a proof of concept would require sharing sensitive data, describe it and email security@academyship.com.au first so we can agree a secure method. Please delete any Academyship or customer data you retained during research once the issue is resolved, to the extent the law allows.
#09What Academyship does next
When we receive a report, we triage it, work to validate and reproduce it, assess its severity, and progress remediation, communicating with you as appropriate. We aim to keep you reasonably informed. We do not publish a fixed acknowledgement or fix deadline in this policy, because those timeframes depend on severity, complexity and resourcing; we will act reasonably and treat genuine security issues seriously.
#10Coordinated disclosure
We ask that you keep the details of a reported vulnerability confidential while we remediate it, and that you coordinate the timing of any public disclosure with us so that users are not put at risk. We will work with you in good faith on reasonable disclosure timing. We do not commit to a fixed disclosure window (such as a guaranteed 90 days) in this policy; we will agree a reasonable approach with you for each report.
#11Recognition and rewards
Academyship does not currently operate a paid bug-bounty program, and this policy does not offer or promise any monetary reward. Where you wish, and once an issue is resolved, we may — with your consent — acknowledge your contribution. There is no entitlement to recognition or payment under this policy.
#12Privacy and record keeping
We use the contact details and information in your report to assess and resolve the issue, to communicate with you, and to keep records of the report and our response. We handle this information in accordance with our Privacy Policy, and we may disclose it where required by law.
#13Incidents, safety concerns and other reports
This page is for reporting security vulnerabilities: weaknesses in Academyship systems that could be exploited. Some situations need a different or more urgent response.
If someone is in immediate danger, call 000 first. Academyship is not an emergency service.
- An active security or privacy incident — for example, you believe someone is exploiting a weakness now, an account has been taken over, or you have received or can see another person's records — email security@academyship.com.au straight away and say at the start of your message that an incident may be in progress. If it involves your Institution's account or records, also tell your Institution. Do not investigate further or keep testing yourself.
- A child-safety or online-safety concern — safety@academyship.com.au (see Child Safety). A security report is not the right route for a safety concern.
For other matters, please use the right channel:
- Privacy questions, requests or complaints: privacy@academyship.com.au;
- Abuse or acceptable-use issues: see the Acceptable Use Policy;
- General support: support@academyship.com.au; and
- Vulnerabilities in a third-party service: report them to that provider.
#14Changes, version history and related documents
We review this policy at least annually (each September) and after a material change to our security process or domain scope. Contact security@academyship.com.au with any questions.
Version history
| Version | Date | Summary of changes |
|---|---|---|
| 1.1 | 9 October 2026 | Aligned the research scope with section 13 of the Acceptable Use Policy: without prior written authorisation, only passive, non-invasive observation of public pages at academyship.com.au is permitted, and authenticated, tenant, payment, signing and credential-verification testing needs prior written authorisation. Made credential-verification, payment and signing weaknesses reportable but not testable against live data; prohibited token enumeration, live payment or signature changes and tenant pivoting; required minimal, redacted evidence; stated that the policy is not a grant of immunity; separated active incidents and safety concerns from vulnerability reports; restated the security.txt section as reader guidance; and added this version history. |
| 1.0 | 12 September 2026 | Initial publication of this security disclosure policy. |
#15Machine-readable security.txt
Where Academyship publishes a machine-readable security contact file under RFC 9116, it is located at https://academyship.com.au/.well-known/security.txt, directs reports to security@academyship.com.au and points to this policy. If that file is unavailable, has expired or differs from this page, use the contact details on this page.