Found something? We’re listening. grateful. on it. all ears.
Security is our first priority. If you’ve spotted a vulnerability, weakness or suspicious activity in uBind, tell us. We acknowledge every report within 24 hours — and we protect good-faith researchers from day one.
From the moment you hit submit,
it’s in our hands.
Here’s exactly what happens to your report, and who owns it at every step.
You report
Submit via this form, or email security@ubind.io directly.
INSTANTWe acknowledge
Ticket ID, and a named contact on our security team.
< 24HTriage
Severity classification, reproduction plan, ownership assigned.
SEVERITY SETInvestigate
Root cause, blast radius, affected tenants and remediation plan.
ROOT CAUSEFix & verify
Patch deployed, tests written, verified with the reporter.
PATCH & RETESTDisclose
Coordinated disclosure, credit (if you want it), CVE if applicable.
COORDINATEDSystem-wide impact
Auth bypass, RCE, mass data exposure, or PII leak affecting multiple tenants.
Single-tenant risk
Privilege escalation, IDOR, or targeted data exposure within a single business.
Contained impact
XSS with limited scope, verbose errors, weak crypto in non-critical flows.
Best-practice fix
Missing headers, minor info disclosure, hardening opportunities.
Tell us what you found.
We’ll take it from here.
The form takes 3–5 minutes. All fields are optional except a way for us to reach you — but the more detail you give, the faster we can act.
- Encrypted transport (TLS 1.3) and at-rest encryption on our systems
- Routed straight to our security team — never a chatbot
- You’ll get a signed acknowledgement + ticket ID within 24 hours
- Safe harbor protections apply to good-faith research (see below)
Good-faith research is welcome here.
We’re committed to protecting security researchers who act in good faith. Here’s the deal — clearly, on one page, without legalese.
What we welcome
- Reporting privately via this form or email before public disclosure
- Testing against your own accounts, or accounts you have permission to use
- Providing us reasonable time to fix before disclosure (default: 90 days)
- Only accessing the minimum data required to demonstrate the issue
- Stopping as soon as impact is proven, and deleting any data obtained
What’s out of scope
- Denial-of-service, load, or resource-exhaustion testing against production
- Social-engineering, phishing, or targeting uBind employees or customers
- Accessing, modifying, or exfiltrating data that isn’t yours
- Physical attacks, or attacks against third-party providers we use
- Automated scans (Burp, Nessus, sqlmap etc.) at anything above light traffic
- Ransom demands, or withholding details pending payment — we never pay a ransom, under any circumstances
We don’t wait for reports.
But we’re grateful when they come.
uBind is a regulated-industry platform. Our security program is continuous, independently audited, and built to satisfy the world’s most demanding insurers and financial institutions.
Regulated to the highest standards.
Every certification we hold is independently audited, renewed on schedule, and published in our audit pack — available on request under NDA.
Security is designed in, not bolted on.
Security is part of the specification for every user story, and reviewed again before any change ships. Independent penetration testing by a CREST-certified firm backs that up — reports are available to customers on request.
Detect, then act.
Platform and infrastructure events are monitored continuously and correlated into alerts. Anything that matters is investigated by our security team under our incident management process.
At rest & in transit.
TLS 1.3 in transit, AES-256 at rest, envelope encryption with KMS-managed keys per tenant. Nothing leaves your region.
Every action, logged.
Immutable, tamper-evident logs of every action across the platform. Available for compliance, forensics, or your own audit team.
Not a security issue? Try one of these.
The form on this page is for security matters only — so we can route it straight to our security team. For everything else, here are the fastest routes.
Product bugs & help
For platform bugs, feature questions, or “how do I…?” — our support team is standing by in the service desk.
Open a ticketBook a demo
Thinking of using uBind, or want a technical deep-dive? Speak to a solutions architect (not a sales bot).
Contact salesCall us direct
For urgent commercial or partnership matters, phone works too. Melbourne office hours (AEST/AEDT).
+61 3 9988 0828Researcher FAQ.
Answers to what most researchers ask before reporting. Can’t find it? Ask us in the form and we’ll answer within a day.
What’s in scope?
How do I test safely without hitting production data?
Will I be publicly credited?
How long until you publicly disclose?
Can I use automated scanners?
Together, we keep insurance unblocked.
Whether it’s a critical vulnerability or a minor observation, we want to hear from you. Thank you for helping us stay secure.