Vulnerability disclosure policy
Last updated: 27 Aug 2025
This policy gives security researchers a point of contact to directly submit their research findings if they believe they have found a potential security vulnerability within the Digital Transformation Agency.
The security of our systems is a top priority, and we take every care to keep them secure. Despite our efforts, there may still be vulnerabilities.
We are keen to engage with the security community. This policy allows security researchers to share their findings with us. If you think you have found a potential vulnerability in one of our systems, services or products, please tell us as quickly as possible.
We will not compensate you for finding potential or confirmed vulnerabilities.
This policy covers:
This policy does not cover:
To report a vulnerability, email us with enough detail so we can reproduce your steps.
If you report a vulnerability under this policy, you must keep it confidential. Do not make your research public until we have finished investigating and fixed or mitigated the vulnerability.
A point of contact for users to directly submit their research findings if they believe they have found a potential security vulnerability within the Digital Transformation Agency.
Email: vulnerabilitydisclosure@dta.gov.au
We will: