Security researchers

Found a vulnerability? Tell us privately.

We welcome good-faith reports that help protect Vericode customers and verification recipients. Use the channel and boundaries below so we can investigate without creating additional risk.

[email protected]
How to report

Give us enough to reproduce the issue safely.

Email [email protected] with the affected service, vulnerability type, reproduction steps, observed impact and any minimal proof needed to demonstrate the issue. Include a safe contact method and whether you want public recognition.

Do not include personal information, credentials or customer records unless strictly necessary. If sensitive material is unavoidable, ask us to agree on a safer transfer method before sending it. Report promptly and keep the issue private while we investigate.

Response commitment

Vericode acknowledges reports on a best-effort basis and will keep you updated as the investigation progresses. Recognition—a public thank-you, with your permission—is offered in place of a bounty program at this stage.

Research boundaries

What is in scope—and what is not.

In scope

  • vericode.com.au — the marketing site
  • app.vericode.com.au — the workspace application and Vericode code in Sidekick
  • api.vericode.com.au — Vericode's production API

Sidekick and the workspace are in scope for vulnerabilities in Vericode's own code.

Out of scope

  • Denial-of-service, load or automated scanning that degrades service
  • Social engineering of Vericode staff or customers
  • Physical-security testing
  • Spam or volumetric testing against SMS or email delivery paths
  • Provider-side infrastructure belonging to Azure, WorkOS, Stripe, MobileMessage, ClickSend, Cloudflare or Loops

Report vulnerabilities in a provider's own infrastructure directly to that provider. A vulnerability in Vericode's integration code remains in scope.

Safe harbour

Good-faith research within this policy will not trigger legal action from Vericode.

Vericode will not pursue civil or criminal legal action, or notify law enforcement, for good-faith research that follows this policy: avoid privacy violations, data destruction and service disruption; do not access or modify data beyond what is needed to demonstrate the issue; and report the vulnerability promptly and privately through the channel above.

This safe harbour does not cover conduct outside these boundaries, unlawful activity unrelated to the research, or demands made through extortion. If you are unsure whether a proposed test is safe, contact us first and wait for written agreement.

Review the wider security posture.

This disclosure process is one part of Vericode's security program. It is not a certification or a replacement for customers' own security and compliance obligations.