IronbarkAML
Vulnerability disclosure · published 2026-04-25

Found something? Tell us.

We treat security researchers as collaborators. If you find a vulnerability in any Ironbark surface, send a report and we will respond.

How to report

Email security@ironbarkaml.com.au. PGP key on request. Alternatively, use /.well-known/security.txt (RFC 9116).

Include: a description of the issue, reproduction steps, your impact assessment, and contact preference. If you can include a proof of concept that does not exfiltrate customer data, that helps us triage faster.

Our commitments

  • Acknowledge receipt within 2 business days
  • Triage and provide an initial assessment within 5 business days
  • Keep you informed at meaningful intervals (no more than every 14 days during remediation)
  • Credit you on this page after fix, with your consent
  • Pay a bug bounty at Phase 4 onwards (Immunefi for smart contracts; HackerOne for application surface)

Scope

In scope:

  • ironbarkaml.com.au and its subdomains
  • The Ironbark API surface (api.ironbarkaml.com.au, when live)
  • Mobile / agent surfaces and SDKs (Phase 4+)
  • Smart contracts on testnet and mainnet (Phase 4+)

Out of scope:

  • Sub-processor infrastructure (report directly to AWS / Cloudflare / Supabase / etc.)
  • Theoretical issues without practical exploitability
  • Social engineering of staff or customers
  • Physical security
  • Denial-of-service attacks

Safe harbour

We will not pursue legal action against researchers who:

  • Make a good-faith effort to avoid privacy violations and disruption to others
  • Do not exploit, exfiltrate, modify, or destroy customer data
  • Do not perform research that violates AU or applicable foreign law
  • Give us reasonable time to fix before public disclosure (90 days default; we will agree shorter on critical issues)

Acknowledgements

The following researchers have responsibly disclosed issues to us. We are grateful.

(List populates as disclosures land. Be the first.)

Last reviewed: 2026-04-25.

Reference: NIST SP 800-61 Rev. 3, RFC 9116 (security.txt), and Policy 07 (Incident Response).