How to report
Email security@ironbarkaml.com.au. PGP key on request. Alternatively, use /.well-known/security.txt (RFC 9116).
Include: a description of the issue, reproduction steps, your impact assessment, and contact preference. If you can include a proof of concept that does not exfiltrate customer data, that helps us triage faster.
Our commitments
- Acknowledge receipt within 2 business days
- Triage and provide an initial assessment within 5 business days
- Keep you informed at meaningful intervals (no more than every 14 days during remediation)
- Credit you on this page after fix, with your consent
- Pay a bug bounty at Phase 4 onwards (Immunefi for smart contracts; HackerOne for application surface)
Scope
In scope:
- ironbarkaml.com.au and its subdomains
- The Ironbark API surface (api.ironbarkaml.com.au, when live)
- Mobile / agent surfaces and SDKs (Phase 4+)
- Smart contracts on testnet and mainnet (Phase 4+)
Out of scope:
- Sub-processor infrastructure (report directly to AWS / Cloudflare / Supabase / etc.)
- Theoretical issues without practical exploitability
- Social engineering of staff or customers
- Physical security
- Denial-of-service attacks
Safe harbour
We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid privacy violations and disruption to others
- Do not exploit, exfiltrate, modify, or destroy customer data
- Do not perform research that violates AU or applicable foreign law
- Give us reasonable time to fix before public disclosure (90 days default; we will agree shorter on critical issues)
Acknowledgements
The following researchers have responsibly disclosed issues to us. We are grateful.
(List populates as disclosures land. Be the first.)
Last reviewed: 2026-04-25.
Reference: NIST SP 800-61 Rev. 3, RFC 9116 (security.txt), and Policy 07 (Incident Response).