Security

Reporting a security issue

Last updated: 17 September 2026

We sell security engineering. If you have found a weakness in something we run, we want to hear about it, and we will treat you well for telling us.

How to report

Email security@rglabs.com.au.

Include enough for us to reproduce the issue: the affected host or endpoint, the steps, and what you were able to demonstrate. A short proof of concept helps. Screenshots are fine.

If the report contains sensitive detail, request our PGP key in your first message and we will provide it before you send the specifics.

What we commit to

We are a small business. We have set these timelines to ones we can actually meet rather than ones that sound impressive. If we miss one, tell us and we will explain why.

In scope

Out of scope

Conduct we ask for

Acting outside this scope, or outside this conduct, takes you outside the protections above.

Rewards

We do not currently operate a paid bug bounty. We are a small business and would rather be honest about that than imply otherwise. What we offer is a fast response, a real fix, public credit if you want it, and a direct line to the engineer rather than a ticket queue.

Resolved reports

Date Summary Severity Reporter Status
— No reports received to date — — —