Public vulnerability disclosure policy

Our policy is based on the NCSC Responsible Disclosure Guidelines.

POLICY

If you identify a security issue with our systems, please notify us so that REANNZ can take steps to investigate and respond to the issue. These guidelines are designed to help both you as a security researcher, and REANNZ, when you find a security issue with our systems.

OUR COMMITTMENT

We will treat all information you share with us confidential within REANNZ. Any information you provide will be reviewed and responded to within seven days. We will work with you to understand and resolve the issue as quickly as practicable.  

 

If the reported vulnerability results in remediation or improvement of the security posture, we may choose to acknowledge the security researcher’s contribution by listing them on the acknowledgements page with their consent. 

 

CONTACT INFORMATION

The best method for contacting our security team is via our email address help@reannz.co.nz. You may encrypt the information using the provided PGP key, which can be found in the security.txt file (https://www.reannz.co.nz/.well-known/security.txt). 

 

To start using it, you'll need to install an OpenPGP/GPG software on your computer. Below you'll find a list of possible solutions for your operating system: 

 

 

Please import the public key into your local OpenPGP Key-Manager.

Find anything about our products, services, and more. Enter a query in the search input above.