Responsible disclosure policy.
Clear guidelines. Safe harbour.
We welcome constructive security research. Here is how to report a vulnerability to us.
Research in good faith is protected.
We consider research authorised and will not pursue legal action provided that you:
- Conduct all testing strictly within the boundaries set out on this page.
- Make a good-faith effort to avoid privacy violations, data loss and outages.
- Do not access, download or change data belonging to another party.
- Do not exploit a vulnerability beyond the minimum steps needed for proof of concept.
- Give us a reasonable opportunity to investigate and remediate before disclosing publicly.
- Comply with applicable laws and act without malicious or extortionate intent.
If you have questions about whether an activity falls within safe harbour, ask us at [email protected] before proceeding.
What is strictly out of scope.
The following activities are strictly prohibited and fall outside safe harbour protection:
- Denial of service (DoS, DDoS) or resource exhaustion testing.
- Social engineering, phishing or spear-phishing directed at Sorami personnel or partners.
- Physical security testing of residences, offices or third-party facilities.
- Automated vulnerability scanners generating high-volume request bursts.
- Direct attacks against third-party SaaS vendors, DNS or hosting infrastructure.
For context on how we conduct external assessments for clients, read our penetration testing scope and our guide on penetration testing scoping.
What to include in your submission.
Please send vulnerability reports to [email protected] with the subject line Security Vulnerability Report.
To help us triage and reproduce the issue quickly, include:
- A clear description of the vulnerability and its potential impact.
- Step-by-step reproduction instructions or a minimal proof of concept.
- Affected endpoints, parameters or components.
- Any screenshots, packet captures or request logs demonstrating the issue.
- Your preferred name or handle if you wish to be credited upon remediation.
Please do not include live credentials or sensitive findings in unencrypted attachments. We handle all reported findings under the principles set out in our trust centre.
What you can expect from us.
- Initial acknowledgment of your report within two business days.
- A candid assessment confirming whether we could reproduce the issue.
- Regular status updates during the investigation and remediation process.
- Notification when the vulnerability has been patched or mitigated.
- Public credit on this page or in our release notes if requested.
We do not offer financial bounties or merchandise. We offer prompt, engineer-to-engineer review and respect for your time.
Practical answers.
Do you pay bug bounties?
No. Sorami does not operate a paid bounty programme. We provide prompt communication, acknowledgment on our site if requested, and confirmed remediations.
What systems are in scope?
Our primary website (sorami.com.au) and any infrastructure directly owned and managed by Sorami Consulting. Third-party providers (such as Cloudflare edge networks or email delivery processors) are out of scope for direct testing.
What happens after I submit a report?
We acknowledge receipt within two business days. We will investigate, confirm whether we can reproduce the issue, and provide an expected timeline for remediation. We will notify you once fixed.
Questions about our security posture?
Learn how we handle client data, findings and credentials in our Trust centre.
Last reviewed: