Security · Responsible Disclosure

Found something? We’re listening. grateful. on it. all ears.

Security is our first priority. If you’ve spotted a vulnerability, weakness or suspicious activity in uBind, tell us. We acknowledge every report within 24 hours — and we protect good-faith researchers from day one.

Our response process

From the moment you hit submit,
it’s in our hands.

Here’s exactly what happens to your report, and who owns it at every step.

Step 01

You report

Submit via this form, or email security@ubind.io directly.

INSTANT
Step 02

We acknowledge

Ticket ID, and a named contact on our security team.

< 24H
Step 03

Triage

Severity classification, reproduction plan, ownership assigned.

SEVERITY SET
Step 04

Investigate

Root cause, blast radius, affected tenants and remediation plan.

ROOT CAUSE
Step 05

Fix & verify

Patch deployed, tests written, verified with the reporter.

PATCH & RETEST
Step 06

Disclose

Coordinated disclosure, credit (if you want it), CVE if applicable.

COORDINATED
Critical

System-wide impact

Auth bypass, RCE, mass data exposure, or PII leak affecting multiple tenants.

Important

Single-tenant risk

Privilege escalation, IDOR, or targeted data exposure within a single business.

Moderate

Contained impact

XSS with limited scope, verbose errors, weak crypto in non-critical flows.

Low

Best-practice fix

Missing headers, minor info disclosure, hardening opportunities.

Submit a report

Tell us what you found.
We’ll take it from here.

The form takes 3–5 minutes. All fields are optional except a way for us to reach you — but the more detail you give, the faster we can act.

  • Encrypted transport (TLS 1.3) and at-rest encryption on our systems
  • Routed straight to our security team — never a chatbot
  • You’ll get a signed acknowledgement + ticket ID within 24 hours
  • Safe harbor protections apply to good-faith research (see below)
Step 1 of 5 — Type of issue

What kind of issue are you reporting?

Pick the one that best fits. We’ll adapt what we ask next.

How serious do you think this is?

Your best judgement — we’ll re-triage on our side, so no wrong answer.

Tell us what you found.

The more specific, the faster we can reproduce and fix. We need a short summary and the steps you took — the rest is optional.

example: https://secure.server.com/some/path/file.js
Not something you can step through — a phishing email, say? Tell us what you saw and when.

Got attachments?

We don’t take file uploads here — send them to us by email instead.

Email attachments to security@ubind.io
Send screenshots, HAR files or PoC videos separately, quoting the ticket ID you get on the next screen.

How should we reach you?

We’ll only use this to update you on the report. Prefer anonymity? Tick the box below.

Received. Thank you.

TICKET SEC-2026-04A9E7

Your report is in the queue. Our security team will be in touch within 24 hours — sooner if it’s critical.

What happens next
  • 1 You’ll receive an acknowledgement email with a signed ticket link
  • 2 An analyst will confirm severity and any clarifying questions
  • 3 We’ll notify you when the fix is deployed and coordinate disclosure
Responsible disclosure policy

Good-faith research is welcome here.

We’re committed to protecting security researchers who act in good faith. Here’s the deal — clearly, on one page, without legalese.

Please do

What we welcome

  • Reporting privately via this form or email before public disclosure
  • Testing against your own accounts, or accounts you have permission to use
  • Providing us reasonable time to fix before disclosure (default: 90 days)
  • Only accessing the minimum data required to demonstrate the issue
  • Stopping as soon as impact is proven, and deleting any data obtained
Please don’t

What’s out of scope

  • Denial-of-service, load, or resource-exhaustion testing against production
  • Social-engineering, phishing, or targeting uBind employees or customers
  • Accessing, modifying, or exfiltrating data that isn’t yours
  • Physical attacks, or attacks against third-party providers we use
  • Automated scans (Burp, Nessus, sqlmap etc.) at anything above light traffic
  • Ransom demands, or withholding details pending payment — we never pay a ransom, under any circumstances
Legal safe harbor
If you make a good-faith effort to comply with this policy, we’ll consider your activity authorised. We won’t pursue civil or criminal action against you, or ask law enforcement to. If a third party brings action against you, we’ll make it clear your work was authorised under this policy.
Our security posture

We don’t wait for reports.
But we’re grateful when they come.

uBind is a regulated-industry platform. Our security program is continuous, independently audited, and built to satisfy the world’s most demanding insurers and financial institutions.

Certifications

Regulated to the highest standards.

Every certification we hold is independently audited, renewed on schedule, and published in our audit pack — available on request under NDA.

ISO/IEC 27001:2022
Information Security Management
PCI-DSS v4.0 APRA CPS 234 GDPR
Secure development

Security is designed in, not bolted on.

Security is part of the specification for every user story, and reviewed again before any change ships. Independent penetration testing by a CREST-certified firm backs that up — reports are available to customers on request.

Specification
Security requirements in every user story
Development
Engineers trained on the OWASP Top Ten and SANS Top 25
Code review
A security review of every change before it ships
In production
Vulnerability scanning and independent penetration testing
Monitoring & response

Detect, then act.

Platform and infrastructure events are monitored continuously and correlated into alerts. Anything that matters is investigated by our security team under our incident management process.

Encryption

At rest & in transit.

TLS 1.3 in transit, AES-256 at rest, envelope encryption with KMS-managed keys per tenant. Nothing leaves your region.

Full audit trail

Every action, logged.

Immutable, tamper-evident logs of every action across the platform. Available for compliance, forensics, or your own audit team.

Other ways to reach us

Not a security issue? Try one of these.

The form on this page is for security matters only — so we can route it straight to our security team. For everything else, here are the fastest routes.

Support ticket

Product bugs & help

For platform bugs, feature questions, or “how do I…?” — our support team is standing by in the service desk.

Open a ticket
Sales & partnerships

Book a demo

Thinking of using uBind, or want a technical deep-dive? Speak to a solutions architect (not a sales bot).

Contact sales
Talk to a human

Call us direct

For urgent commercial or partnership matters, phone works too. Melbourne office hours (AEST/AEDT).

+61 3 9988 0828
Common questions

Researcher FAQ.

Answers to what most researchers ask before reporting. Can’t find it? Ask us in the form and we’ll answer within a day.

What’s in scope?
All uBind-owned production surfaces, primarily *.ubind.io and ubind.insure. Third-party services we integrate with (payment processors, KYC providers, cloud infra) are out of scope — please report those to their maintainers.
How do I test safely without hitting production data?
Use accounts you own — sign up for a free evaluation tenant, or ask us for a sandbox by emailing security@ubind.io. Never test against another customer’s data, even if you can access it.
Will I be publicly credited?
If you’d like credit, absolutely. Tick the credit box on the form and we’ll acknowledge you on our security acknowledgements page (with a link if you wish) once the fix ships. Prefer anonymity? That’s fine too.
How long until you publicly disclose?
We aim to fix and disclose within 90 days. For critical findings, disclosure happens after all affected customers have been notified and remediation is verified. We coordinate the timing with you and give you the option to co-publish.
Can I use automated scanners?
Not against production, please. Light manual testing is fine. Heavy automated scanning (Burp Intruder at rate, sqlmap, DAST tools) will trigger our WAF and get you blocked. If you need to run scanners, ask us for a sandbox — we’re happy to set one up.
Every report matters

Together, we keep insurance unblocked.

Whether it’s a critical vulnerability or a minor observation, we want to hear from you. Thank you for helping us stay secure.

Copied to clipboard