Terra15 Vulnerability Disclosure Policy

Policy Statement

Effective Date: 2026-02-24

At Terra15, we take the security of our products, services, and users seriously. We value the work of the security research community and welcome reports of potential vulnerabilities.

This policy describes how to report vulnerabilities to us, what you can expect from us, and what we ask of you.

Scope

This policy applies to vulnerabilities discovered in the following:

  • Terra15 web applications and progressive web apps (PWAs)
  • Terra15 APIs and backend services
  • Terra15 open-source projects hosted at https://github.com/terra15collab

Out of Scope

The following are excluded from this policy:

  • Third-party applications or services not owned by Terra15
  • Social engineering attacks (e.g., phishing) against Terra15 employees or users
  • Denial-of-service (DoS/DDoS) attacks
  • Physical attacks against Terra15 offices or data centres
  • Findings from automated scanners without a demonstrated proof of concept

Reporting a Vulnerability

Please submit your report to [email protected] and include the following:

  1. A description of the vulnerability and its potential impact
  2. Detailed steps to reproduce the issue (proof of concept)
  3. The affected product, version, URL, or endpoint
  4. Any tools, scripts, or screenshots that help demonstrate the issue
  5. Your contact information for follow-up (optional but appreciated)

What We Ask of You

To ensure the safety of our users and data, we ask that researchers:

  • Act in good faith and make a reasonable effort to avoid privacy violations, data destruction, and disruption of services
  • Do not access, modify, or delete data belonging to other users
  • Do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it
  • Do not exploit the vulnerability beyond what is necessary to demonstrate the issue
  • Comply with all applicable laws in your jurisdiction

What You Can Expect from Us

  • Acknowledgment: We will acknowledge receipt of your report within 3 business days
  • Communication: We will keep you informed of the status of your report and work with you to understand and validate the issue
  • Timely Resolution: We will make a good-faith effort to resolve confirmed vulnerabilities within a reasonable timeframe, typically 90 days depending on complexity
  • Credit: With your permission, we will publicly credit you for the discovery when we publish a fix or advisory
  • No Legal Action: We will not pursue legal action against researchers who discover and report vulnerabilities in accordance with this policy (see Safe Harbor below)

Safe Harbor

Terra15 considers security research conducted in accordance with this policy to be:

  • Authorized with respect to any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy
  • Authorized with respect to any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls
  • Exempt from restrictions in our Terms of Service that would interfere with conducting security research, and we waive those restrictions on a limited basis
  • Lawful, helpful to the overall security of the Internet, and conducted in good faith

You are expected, as always, to comply with all applicable laws. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please reach out to us at [email protected] before going any further.

Policy Changes

We may revise this policy from time to time. The most current version will always be available at https://terra15.com.au/vulnerability-disclosure

Questions?

Contact us at [email protected]

See our Privacy Policy for more information.