Private contact
Email the details to us
Email hello@tempeststudios.com.au with the subject Security vulnerability report. Do not publish an undisclosed vulnerability in a GitHub issue, discussion, pull request, or social post.
- The affected URL, component, or commit
- A description of the issue and its likely impact
- Reproducible steps or a minimal proof of concept
- Relevant request and response details with secrets and personal information removed
- A safe way to contact you for follow-up
What to expect
A coordinated response
We aim to acknowledge security reports within three business days. We will investigate, keep the reporter informed when practical, and coordinate disclosure after a fix or mitigation is available.
Responsible testing
Keep testing safe and proportionate
Make a good-faith effort to avoid privacy violations, service disruption, data destruction, social engineering, physical attacks, denial-of-service testing, and access to data beyond what is necessary to demonstrate the issue.
Stop testing and report the issue if you encounter personal, confidential, or customer data. Tempest Studios does not currently operate a paid bug bounty program.