Legal
Responsible Disclosure Policy
Maxwell Vidler trading as UniMatter ('UniMatter', 'we', 'us', 'our') builds and advises on systems for the legal, clinical, and compliance sectors, where the integrity and confidentiality of information are central to the work. We regard the security of those systems as a continuing obligation rather than a fixed state, and we welcome the assistance of the security research community in identifying weaknesses before they can be exploited. This policy explains how to report a security vulnerability to us, what you may expect from us in return, and the conduct we ask of you.
1. Purpose and commitment
The purpose of this policy is to provide a clear and reliable channel through which security researchers, customers, and members of the public may report vulnerabilities affecting our systems, and to set out the basis on which we will receive and act upon those reports.
Security is a discipline we practise on our own systems and advise upon for others, and we hold ourselves to the standard we advise others to meet. We are committed to identifying, assessing, and remediating security vulnerabilities in a timely manner, and to working constructively and in good faith with those who report them. We value the work of the research community, and we treat a well-founded report not as an accusation but as a contribution to the safety of the people whose information our systems hold.
We define a 'vulnerability' as a weakness in the design, implementation, operation, or configuration of an in-scope asset that could be exploited to compromise the confidentiality, integrity, or availability of that asset or of the information it holds. We define a 'researcher' as any person who identifies and reports a vulnerability to us under this policy.
2. Scope
This policy applies to the assets we own and operate. The following are 'in-scope assets':
- unimatter.com.au and www.unimatter.com.au, and the pages and services they serve;
- the client access surface at unimatter.com.au/portal.
Assets not listed above are out of scope. Where an engagement surface is provisioned to a client, its scope is governed by the engagement, not by this policy.
The following activity is 'out of scope' and is not authorised under this policy:
- testing of, or interference with, third-party services, platforms, or infrastructure that we do not own or control, including services we consume or integrate with;
- social engineering of any kind, including phishing, pretexting, or other attempts to deceive our personnel, contractors, or customers;
- physical attacks against premises, hardware, or personnel;
- denial-of-service testing, volumetric testing, or any technique intended to exhaust, degrade, or interrupt the availability of a service;
- automated scanning conducted at a rate or in a manner that degrades, destabilises, or materially burdens a service;
- any activity requiring access to an account, system, or data that you do not own or are not authorised to access.
Where you are uncertain whether an asset or a technique falls within scope, contact us at the address in clause 5 before proceeding. When in doubt, treat the activity as out of scope until we confirm otherwise.
3. Our commitments to you
Where you report a vulnerability in accordance with this policy, we commit to the following:
- we will acknowledge receipt of your report within 5 business days;
- we will keep you reasonably informed of our progress as we triage, validate, and work to remediate the issue;
- we will not pursue, support, or encourage legal action against you in respect of good-faith security research that is conducted in compliance with this policy, and we will treat such research as authorised conduct for the purposes of our systems;
- where you wish to be identified, and with your consent, we will credit you for your contribution once the issue has been resolved.
These commitments are made by us in respect of our own conduct and our own systems. They are explained further, as they relate to the law, in clause 8.
4. What we ask of you
In return, and as the basis on which the commitments in clause 3 are given, we ask that you:
- act in good faith, and use the access and information you obtain only to identify, understand, and report a vulnerability;
- avoid any conduct that would violate the privacy of others, destroy or corrupt data, or degrade, interrupt, or impair the operation of a service;
- interact only with accounts and data that you own or that you are expressly authorised to access, and do not access, modify, or retain the data of any other person;
- access only the minimum information necessary to demonstrate the existence and impact of a vulnerability, and cease testing once that has been established;
- do not exfiltrate, retain, publish, or share any data accessed in the course of your research, and securely delete any such data once your report has been submitted;
- give us a reasonable period to investigate and remediate an issue before you disclose it, in whole or in part, to any third party or to the public;
- do not demand, solicit, or accept payment, and do not condition disclosure of a vulnerability on any payment or other consideration.
Conduct that departs from this clause falls outside the protections described in clauses 3 and 8.
5. How to report
Report a vulnerability to us by email at security@unimatter.com.au. To help us assess and address your report efficiently, please include:
- a clear description of the vulnerability and the asset or component affected;
- the steps required to reproduce the issue, including any proof-of-concept material, request or response logs, or screenshots;
- an explanation of the impact, including what an attacker could achieve by exploiting the issue;
- your contact details, and a statement of whether you wish to be credited.
We publish machine-readable contact and policy details, in accordance with the relevant standard, at unimatter.com.au/.well-known/security.txt.
Please submit reports in English. We ask that you do not disclose the vulnerability publicly until we have confirmed that it has been resolved, or until the period described in clause 6 has elapsed.
6. Our process
On receipt of a report, we will deal with it as follows:
- Triage. We will acknowledge the report within the timeframe in clause 3, assess it for completeness, and assign it an initial severity.
- Validation. We will seek to reproduce and confirm the vulnerability, and may contact you for further information or clarification.
- Remediation. Where the vulnerability is confirmed, we will develop, test, and deploy a remediation, prioritised according to its severity and the risk it presents.
- Coordinated disclosure. We will work with you towards coordinated disclosure, and will aim to resolve valid reports within 90 days of acknowledgement. Where an issue is complex or its remediation depends on a third party, we will tell you, and we will agree a revised timeframe with you.
We treat the timeframes in this policy as targets that reflect our intentions in good faith, not as contractual guarantees, and we will keep you informed where a target cannot be met.
7. Recognition
UniMatter acknowledges good-faith researchers and does not operate a paid bounty programme; no payment is offered or implied for the reporting of a vulnerability. Where you have reported a valid, in-scope vulnerability in accordance with this policy, and with your consent, we will credit you once the issue has been resolved.
8. Legal note
This policy does not authorise, and must not be read as authorising, any conduct that is unlawful under the laws of the Commonwealth of Australia or of the State of Queensland, including the laws governing unauthorised access to, and impairment of, computer systems and data. Nothing in this policy grants you any right in respect of systems, data, or services belonging to any third party.
Within those limits, we will treat security research conducted in good faith and in compliance with this policy as authorised conduct in respect of our systems, and, as stated in clause 3, we will not pursue, support, or encourage legal action against a researcher in respect of such research. Where your conduct departs from this policy, this assurance does not apply, and we reserve all rights available to us at law.
This policy is governed by, and is to be construed in accordance with, the laws in force in the State of Queensland, Australia, and the operation of this policy is consistent with applicable law. This policy does not create any contractual relationship, and it does not limit or exclude any right or protection available to you under the law.
9. Changes to this policy
We may amend this policy from time to time, so that it continues to reflect our systems, our practice, and the expectations of the research community. The version and effective date shown at the head of this policy indicate the current iteration. We encourage you to consult the current version, and the machine-readable details at unimatter.com.au/.well-known/security.txt, before submitting a report.
10. How to contact us
For any matter arising under this policy, including the report of a vulnerability or a question about its scope, contact us at:
- Security contact: security@unimatter.com.au
- General contact: administrator@unimatter.com.au
- Entity: Maxwell Vidler trading as UniMatter, Level 1, 16 McDougall Street, Milton, Queensland 4064, Australia
We are grateful to those who take the time to report vulnerabilities responsibly, and we will deal with every report on that footing.