Responsible Disclosure Policy

Last updated: 4 August 2026

We take the security of this website and the information our members entrust to us seriously. If you believe you have found a security vulnerability in any of our systems, we want to hear from you, and we will work with you to resolve it quickly.

Report a vulnerability:
security@hldgroup.org

1. Scope

This policy covers the Armidale Regional Chamber of Commerce website and the member-facing services operated on our behalf by HLD Software Group. Third-party services we rely on (for example payment processing and email delivery) are outside this scope and should be reported directly to those providers.

2. How to Report

Email security@hldgroup.org with:

  • A clear description of the issue and the potential impact.
  • The steps required to reproduce it, including any URLs, requests or accounts involved.
  • Any supporting material such as logs, screenshots or a short proof of concept.
  • How you would like to be credited, if you would like acknowledgement.

Please report privately and give us a reasonable opportunity to fix the issue before disclosing it publicly or to any third party.

3. Our Commitment to You

  • We aim to acknowledge your report within five business days.
  • We will keep you informed of our progress as we investigate and remediate.
  • We will not pursue legal action against researchers who follow this policy in good faith.
  • We will credit you for your finding if you would like us to.

We do not currently operate a paid bug bounty program, and no payment or reward should be expected for a report.

4. Testing Guidelines

When investigating a potential vulnerability, please:

  • Only test against accounts and data that belong to you.
  • Stop as soon as you have confirmed an issue, and do not access, modify, or download data belonging to anyone else.
  • Avoid anything that could degrade our service or affect other users, including denial of service, automated scanning at high volume, spam, and social engineering of our staff or members.
  • Delete any of our data you obtained during testing once your report is resolved.

Testing that goes beyond these guidelines is not authorised under this policy.

5. Out of Scope

The following are generally not accepted as vulnerabilities under this policy:

  • Reports produced solely by automated scanners with no demonstrated impact.
  • Missing security headers, cookie flags, or TLS configuration issues with no working exploit.
  • Rate limiting or brute force concerns on non-sensitive endpoints.
  • Self-inflicted issues that require the victim to paste code into their own browser console.
  • Vulnerabilities affecting only unsupported or end-of-life browsers.

6. Contact

Security reports: security@hldgroup.org

For anything that is not a security issue, please contact the Chamber directly:

Armidale Regional Chamber of Commerce
56 Kruideniers Rd.
Armidale, NSW, Australia
Email: info@armidalechamber.com.au
Phone: 477 977 679