---
url: /security.md
---
# Security

This page contains information about the use of security at SuperAPI.

::: info
Found a vulnerability in our software? Please reach out to us at security@superapi.com.au
:::

## Reporting a vulnerability

Email **security@superapi.com.au**. The same address is published in our [security.txt](https://api.superapi.com.au/.well-known/security.txt) and reachable through the report link on our [Trust Centre](https://trust.superapi.com.au/).

This applies to the internet-facing services we operate, including our customer platform, our onboarding products and our superannuation gateway.

Please tell us what you found, how you found it, what you believe the impact is, and how to reproduce it. If you intend to disclose the issue publicly, tell us that and tell us when. A report that is only automated scanner output, with no demonstrated impact, is given lower priority.

## Safe harbour

We will not pursue legal action against you for reporting a vulnerability to us in good faith, provided that in finding it you:

* did not harm SuperAPI, our customers, their members or our partners
* did not access, alter, destroy or remove data that was not your own
* did not degrade or interrupt a service, including by denial of service testing
* did not try to obtain information or access by deceiving our people, our customers or our suppliers
* did not attempt physical entry to any premises
* tested only against your own account, data or systems, or had the consent of the party whose systems you tested
* complied with the laws that apply where you are and where we are
* did not disclose the vulnerability publicly before a timeframe we agreed with you had passed

Within those bounds we authorise the activity for the purpose of improving our systems. Activity outside them is not covered.

## What you can expect from us

* an acknowledgement of your report within 10 business days
* an assessment and, once we have triaged it, an indication of when we expect to have it resolved
* an update when that expectation changes, and on request
* notification when the vulnerability has been resolved
* credit for the discovery once the vulnerability has been validated and resolved, if you want it

We do not operate a paid bug bounty and do not offer payment for reports.
