Trust & Safety
Vulnerability Disclosure Policy
Our commitment
Itadly takes the security of its products and services seriously. We welcome reports of security vulnerabilities from researchers, customers, and the public, and we are committed to investigating and resolving them in a timely, controlled, and transparent manner. This policy explains what is covered, how to report a vulnerability, what you can expect from us, the rules for testing, and the protections we extend to good-faith security research.
Scope
In scope
- OblitoCLI — the data sanitisation command-line tool (the Common Criteria Target of Evaluation), all supported versions.
- Itadly’s public-facing web properties (e.g.
itadly.io).
Out of scope (systems)
- Third-party infrastructure, services, and platforms that Itadly does not own or operate. We cannot authorise security research on third parties, and they are not bound by this policy.
- The Oblito portal, backend services, and supporting network infrastructure are outside the evaluated TOE boundary; you may report issues affecting them through the same contact, but they are handled under separate operational controls.
How to report
Report security vulnerabilities and suspected flaws by email to security@itadly.io. Our reporting contact is also published in machine-readable form at https://itadly.io/.well-known/security.txt, in accordance with RFC 9116.
To help us triage and reproduce the issue quickly, please include where possible:
- A unique reference or title for the issue, and the date identified.
- The affected product, component, and version.
- A clear description of the vulnerability, its nature, and potential impact.
- Steps to reproduce, including any conditions required to trigger it.
- Your assessment of severity and any security or compliance implications.
What you can expect from us
- Acknowledgement of your report within 3 business days of receipt.
- Initial triage assessment (validity and severity) within 10 business days.
- Progress updates at regular intervals — at least every 14 days — until the issue is resolved.
- Remediation prioritised by severity. Our target timeframes are: Critical — corrective action prepared as a high priority (target within 48 hours of confirmation); High — within 7 days; Medium/Low — incorporated into the next scheduled release or planned update cycle.
- Notification when a fix is released.
- Credit — with your consent, we will acknowledge your contribution (for example, in release notes).
Rewards: Itadly does not currently operate a paid bug-bounty program and does not offer monetary rewards. Recognition is non-monetary, as described above.
Rules of engagement
To remain authorised under this policy and its safe-harbour provisions, you must not:
- Perform denial-of-service (DoS/DDoS) testing or any action that degrades or interrupts service availability.
- Conduct social engineering, phishing, or physical attacks against Itadly staff, users, suppliers, or facilities.
- Access, test against, or interact with live customer or production data; use only your own test data and accounts.
- Perform destructive testing, modify or delete data, or establish persistence (e.g. backdoors).
- Run automated scanning that generates excessive traffic or otherwise degrades service.
- Access, download, or retain more data than the minimum necessary to demonstrate the issue.
Handling data you encounter
If, during good-faith research, you encounter personal data, credentials, or other sensitive information:
- Stop immediately and do not access, copy, transfer, or disclose any more than the minimum necessary to demonstrate the vulnerability.
- Do not store, share, or retain such data, and securely delete any incidental copies once your report has been submitted.
- Notify Itadly promptly and include only the minimum information required to reproduce and assess the issue in your report.
Out-of-scope findings
We generally will not action the following without a demonstrated, realistic security impact:
- Missing security headers or best-practice configuration recommendations without a working exploit.
- Self-XSS, clickjacking on pages without sensitive actions, or other theoretical issues with no practical impact.
- Reports generated solely by automated tools without supporting analysis or proof of concept.
- Rate-limiting or brute-force concerns without demonstrated impact.
- Use of outdated software versions absent a specific, exploitable vulnerability.
- Issues affecting only unsupported or end-of-life browsers, platforms, or systems.
Coordinated disclosure
We ask that you practise coordinated disclosure:
- Provide Itadly with your report before any public disclosure of the vulnerability.
- Allow Itadly a period of up to 120 days from your disclosure to remediate, test, and distribute a fix prior to publication.
- Avoid privacy violations, data destruction, service degradation, or any action that could harm individuals or the public during your research.
Safe harbour
Itadly supports the protection of organisations and individuals engaged in Good Faith Security Research — accessing a system solely for good-faith testing, investigation, or correction of a security vulnerability, carried out to avoid harm to individuals or the public, where findings are used primarily to improve security.
For activity conducted in accordance with this policy, Itadly:
- Will not bring or support legal action against you for Good Faith Security Research, including for bypassing technological measures used to protect in-scope applications; and
- Will take steps to make known that your activity was authorised Good-Faith Security Research if a third party brings legal action against you.
We waive any relevant restriction in our Terms of Service or Acceptable Use Policy that conflicts with the standard for Good Faith Security Research described here, to the extent such activity does not harm individuals or the public. If you are unsure whether specific conduct is consistent with this policy, contact us at security@itadly.io for clarification before proceeding.
This authorisation and safe harbour apply only to the extent permitted by applicable law. Nothing in this policy authorises activity that is unlawful under applicable Australian law, and you remain responsible for complying with all applicable laws. Safe-harbour protection also does not apply if you do not provide Itadly the disclosure window described above, or if you disclose vulnerability information publicly before notifying Itadly.
Certified product note
OblitoCLI is a Common Criteria – evaluated product. Vulnerabilities assessed as affecting its certified security functionality are also reported to the relevant Australian Information Security Evaluation Facility under the AISEP, so the impact on continuing assurance can be assessed.
Confidentiality and general enquiries
We treat reports confidentially and handle your contact details and any personal information in accordance with our privacy obligations; any public acknowledgement is coordinated with you in advance. For general product bugs or support requests that are not security vulnerabilities, please use Itadly’s standard support channel rather than the security mailbox.
Version 1.0 · Last updated 25 June 2026 · Review at least annually and before the security.txt Expires date.