Public vulnerability disclosure policy
Our policy is based on the NCSC Responsible Disclosure Guidelines.
POLICY
If you identify a security issue with our systems, please notify us so that REANNZ can take steps to investigate and respond to the issue. These guidelines are designed to help both you as a security researcher, and REANNZ, when you find a security issue with our systems.
OUR COMMITTMENT
We will treat all information you share with us confidential within REANNZ. Any information you provide will be reviewed and responded to within seven days. We will work with you to understand and resolve the issue as quickly as practicable.
If the reported vulnerability results in remediation or improvement of the security posture, we may choose to acknowledge the security researcher’s contribution by listing them on the acknowledgements page with their consent.
CONTACT INFORMATION
The best method for contacting our security team is via our email address help@reannz.co.nz. You may encrypt the information using the provided PGP key, which can be found in the security.txt file (https://www.reannz.co.nz/.well-known/security.txt).