Report a vulnerability
Email security@nebulaplatform.com.au. Include the affected service or URL, the observed behaviour, reproduction steps, the potential impact and enough evidence to validate the report. State any deadline or disclosure plan that may affect coordination.
Do not include customer content, credentials, private keys or other personal information unless it is necessary to explain the issue. Redact evidence where practical.
Proposed scope
The proposed policy would cover first-party paths served from https://www.nebulaplatform.com.au. Any other hostname would be outside that proposed scope unless Nebula confirms it in writing for the report. Third-party services and infrastructure remain governed by their respective providers. The final policy may provide for reports about a dependency or provider to be passed to the responsible party.
Proposed research conditions
Under a final policy, security research would need to:
- use only accounts and data the researcher owns or is authorised to use;
- stop testing and report promptly if customer data or another person's account is accessed;
- avoid changing, deleting, downloading or retaining data beyond the minimum needed to demonstrate the issue;
- avoid denial of service, high-volume automated testing, spam, phishing, social engineering and physical testing;
- avoid malware, persistence, destructive payloads and attempts to pivot into third-party systems; and
- allow reasonable time for validation and remediation before public disclosure.
Proposed good-faith position
Subject to legal approval, Nebula intends not to initiate legal action solely because of good-faith security research that follows the final policy. This draft does not create a safe harbour, authorise unlawful conduct, bind a third party or prevent action needed to protect customers, the service or other people. Contact Nebula before testing if the permitted scope is unclear.
Proposed response and disclosure
For the proposed policy, a business day is Monday to Friday, excluding Queensland public holidays. The proposed acknowledgement target is five business days. It is not an operating commitment until mailbox coverage, a backup mailbox owner and operator capacity are verified. Reports would be prioritised by exploitability, affected data and customer impact.
Coordinated disclosure timing would be agreed case by case under the final policy. This draft offers no bug bounty, payment or public acknowledgement.
Other security enquiries
Procurement and security control questions are covered on the Security page. Suspected personal information breaches should also be reported to security@nebulaplatform.com.au.