Security
Reporting a security issue
Last updated: 17 September 2026
We sell security engineering. If you have found a weakness in something we run, we want to hear about it, and we will treat you well for telling us.
How to report
Email security@rglabs.com.au.
Include enough for us to reproduce the issue: the affected host or endpoint, the steps, and what you were able to demonstrate. A short proof of concept helps. Screenshots are fine.
If the report contains sensitive detail, request our PGP key in your first message and we will provide it before you send the specifics.
What we commit to
- Acknowledgement within 5 business days of your report reaching us
- An initial assessment, with our view of severity, within 10 business days
- Regular updates until the issue is resolved or we explain why we are not acting on it
- Credit in our disclosure record if you want it, and none if you do not
- We will not take legal action against you, and we will not ask your employer or your ISP to, provided you stay within the scope and conduct below
We are a small business. We have set these timelines to ones we can actually meet rather than ones that sound impressive. If we miss one, tell us and we will explain why.
In scope
rglabs.com.auportal.rglabs.com.auand the client portalmta-sts.rglabs.com.aurglabs.au,rglabs.online- Our published DNS, email authentication and TLS configuration
Out of scope
- Client environments. We hold read-only access to third-party cloud tenants. Testing against a client's environment is not authorised by us and we cannot authorise it on their behalf. Do not attempt it.
- Denial of service, volumetric testing, or anything degrading availability for others
- Social engineering of RG Labs personnel, clients or suppliers
- Physical attacks against premises or equipment
- Findings from an automated scanner with no demonstrated impact
- Missing security headers, weak ciphers or configuration issues with no demonstrated exploit path. Tell us anyway if you like — we will fix them, but they are not eligible for the commitments above
- Issues in third-party services we consume. Report those to the provider, and let us know so we can track it
- Reports requiring physical access to a device, a compromised endpoint, or a man-in-the-middle position on the victim's network
Conduct we ask for
- Access only data that is your own, or test data you created. If you encounter client data, stop, do not retain a copy, and tell us immediately
- Do not modify, delete or exfiltrate data
- Do not run tests that affect other users
- Give us reasonable time to remediate before public disclosure. 90 days is our default, and we are happy to discuss shorter for low-risk issues or longer for complex ones
- One report per issue
Acting outside this scope, or outside this conduct, takes you outside the protections above.
Rewards
We do not currently operate a paid bug bounty. We are a small business and would rather be honest about that than imply otherwise. What we offer is a fast response, a real fix, public credit if you want it, and a direct line to the engineer rather than a ticket queue.
Resolved reports
| Date | Summary | Severity | Reporter | Status |
|---|---|---|---|---|
| — | No reports received to date | — | — | — |