Consumer Protection

Responsible Disclosure Policy

The security and privacy of our customers and systems is a top priority. We welcome ethical security researchers who help us identify vulnerabilities.

This Responsible Disclosure Policy outlines how we collaborate with security researchers and what we expect from those who wish to help improve our security.

Who This Policy Is For

This policy is designed for:

  • Ethical security researchers and penetration testers not engaged under contract with LIVA Telecom
  • Cybersecurity professionals
  • Customers or users who discover vulnerabilities*
  • Technical partners or vendors

If you belong to any of these groups and believe you've discovered a security issue, we want to hear from you.

What You Can Test

Responsible security research may be conducted on LIVA Telecom systems, products, and services that are:

  • Internet-accessible and public facing
  • Within your authorised access level (for example, customer or user portal access)

If you are unsure whether something is in scope, please contact us.

Rules of Engagement

When conducting research, please:

  • Avoid denial-of-service attacks or anything that degrades service
  • Act in good faith and avoid causing harm or disruption
  • Report vulnerabilities to us as soon as reasonably possible
  • Only test systems you are authorised to access
  • Never access, modify, store, or exfiltrate customer data or LIVA Telecom intellectual property
  • Do not use social engineering, phishing, or physical security attacks
  • Do not test third-party systems, applications, or services
  • Avoid privacy violations and do not destroy or corrupt data

What's Not Allowed

The following activities are strictly prohibited:

  • Data modification or destruction
  • Any activity that violates the law
  • Testing third-party systems
  • Social engineering, phishing, or impersonation
  • Sending spam or unauthorised communications
  • DoS or DDoS attacks
  • Physical attacks on property or personnel
  • Uploading or linking to malware
  • Clickjacking
  • Accessing accounts or data that do not belong to you
  • Using deceptive techniques to bypass security

Out-of-Scope Vulnerabilities

Please do not report vulnerabilities that cannot be directly exploited or do not pose a risk. Examples include:

  • Weak or misconfigured SSL/TLS certificates
  • Misconfigured DNS records (SPF, DKIM, DMARC)
  • Missing HTTP security headers
  • Theoretical CSRF or cross-site framing attacks
  • Automated scan results without manual verification
  • Vulnerabilities without a working exploit
  • MITM or physical access-based attacks
  • Issues requiring excessive user interaction
  • Content spoofing without HTML/CSS impact
  • CSRF on non-sensitive pages
  • Public files with no sensitive content
  • Non-sensitive cookie flags
  • Vulnerable libraries with no exploit path
  • Issues affecting outdated browsers
  • Static resources in public buckets
  • Verbose error messages or software version disclosures
  • Rate limiting issues on non-auth endpoints
  • Open redirects without security impact
  • CSV injection without an exploit

How to Report a Vulnerability

If you find a security issue, please submit it via our contact us web form, providing as much detail as possible, including:

  • Description of the vulnerability
  • Affected URLs, services, or assets
  • Steps to reproduce the issue
  • Proof-of-concept code or screenshots
  • Test accounts or objects used
  • Your contact details (optional)

Additional guidelines:

Submit reports in English. Keep your findings confidential until resolved. Avoid exploiting the vulnerability. Submit one vulnerability per report. We will not share your contact details without your permission unless required by law.

We will not share your contact details without your permission unless required by law. Reports unrelated to security vulnerabilities will not receive a response.

What Happens After You Report

Once your report is submitted, we will acknowledge it within 48 hours. We may contact you for additional information and will keep you informed of our progress.

Safe Harbour

We appreciate your efforts and aim to protect researchers acting in good faith. We will not take legal action if you follow this policy, stop testing once a vulnerability is confirmed, and cooperate with us on coordinated disclosure.

Compensation

LIVA Telecom does not offer monetary rewards or compensation for vulnerability disclosures. Submissions are voluntary and help us strengthen security for all customers.

Questions or complaints?

LIVA Telecom | Level 49, 8 Parramatta Square, Parramatta NSW 2150 | ABN: 32 621 849 518