Report a security concern.
If you believe you have identified a security issue affecting CommsPliant, please report it to us so we can investigate it promptly and responsibly.
This page is for genuine security concerns relating to the CommsPliant service, website or supporting infrastructure.
What to report
Examples include:
- suspected vulnerabilities;
- unintended access to data or functionality;
- authentication or access-control issues;
- exposed credentials or secrets;
- security behaviour that appears inconsistent with the intended controls;
- other concerns that could affect the confidentiality, integrity or availability of CommsPliant.
If you are unsure whether something is a security issue, you can still report it through the Contact page and we will assess it.
What to include
Please provide enough information for us to understand and reproduce the issue where possible. Useful details may include:
- a clear description of the issue;
- the page, feature or service affected;
- the date and approximate time observed;
- steps to reproduce the issue;
- screenshots or other supporting evidence where safe to share;
- your preferred contact details for follow-up.
Please do not include unnecessary customer personal data, passwords, access tokens or other sensitive information in the initial report.
What not to do
Please do not:
- access, modify or retain data that is not yours;
- disrupt the service or intentionally degrade availability;
- use social engineering, phishing or physical security testing;
- attempt destructive testing;
- publicly disclose a suspected issue before CommsPliant has had a reasonable opportunity to assess and address it.
This page is a responsible reporting channel. It does not create any entitlement to payment or reward.
What happens after you report
Security concerns are submitted through the CommsPliant Contact page.
We will review the information provided, assess the potential impact and handle the issue through the CommsPliant incident-response process where appropriate.
We may contact you for further information if needed.
Where the issue is confirmed, remediation and follow-up will be prioritised according to the nature and severity of the risk.
FAQ
You should report suspected vulnerabilities, unintended access to data or functionality, authentication or access-control issues, exposed credentials or secrets, or other behaviour that could affect the confidentiality, integrity or availability of CommsPliant.
Use the CommsPliant Contact page and select or describe the issue as a security concern. Please include enough information for us to understand and investigate the issue.
Please do not include unnecessary customer personal data, passwords, access tokens or other sensitive information. Share only what is needed to explain the issue safely.
CommsPliant will review the information, assess the potential impact and handle the issue through the incident-response process where appropriate. We may contact you for more information, and confirmed issues are prioritised according to their nature and severity.
If you're unsure whether something should be reported as a security issue, contact us and we'll help you route it appropriately.
Still need help reporting a concern?
If you're unsure whether something should be reported as a security issue, contact us and we'll help you route it appropriately.
Report a security concern