Security

Responsible Disclosure.

If you have found a security vulnerability in Proofmarc, we want to hear about it before anyone else does. This page tells you how to reach us, what is in scope, and how we will respond.

Encrypted report: security@proofmarc.com.au

Reporting a vulnerability

Send a detailed report to security@proofmarc.com.au. If the finding is sensitive, encrypt it using our published PGP key (fingerprint available on request).

A good report includes:

Safe harbour
If you act in good faith, follow this policy, and do not access, modify, or destroy customer data, Proofmarc will not pursue civil action or report you to law enforcement for your research.

Scope

In scope
  • proofmarc.com.au and subdomains
  • The Proofmarc SaaS console
  • The Proofmarc public SDK packages
  • Authentication, authorisation, and tenant isolation
  • Customer data confidentiality, integrity, availability
Out of scope
  • Denial-of-service attacks against production
  • Social engineering of Proofmarc staff or customers
  • Physical attacks against offices or hardware
  • Findings already disclosed in our public advisories
  • Best-practice recommendations without a demonstrable impact

Our response timeline

Within 2 business days
Acknowledge receipt of your report and assign a tracking reference.
Within 7 business days
Triage the finding and confirm whether we have reproduced it.
Within 30 days
Provide a remediation plan with an indicative ship date.
On fix
Notify you, credit you (if you wish), and publish an advisory.

What we will and will not do

We will

We will not