Vulnerability Disclosure Policy
Help keep Willed safe.
We welcome reports that help protect our users and their information. Public security reporting remains open, without a standing offer of monetary rewards. Paid security testing is arranged separately in writing.
Responsible disclosure
How to report an issue.
Programme change: 8 September 2026
From publication of this notice on 8 September 2026 (AEST), our public paid bug bounty programme is closed to new research. New unsolicited reports under this policy do not carry a monetary-reward offer. Please continue to report security issues to security@willed.com.au.
Existing submissions will be assessed under the terms that applied to them, and agreed awards will be honoured. This change does not retrospectively reject reports or introduce new award exclusions. If you began research in good faith in reliance on the previous terms before this notice was published, include that context when you contact us so we can assess that work under the applicable previous terms. This is not permission to continue production testing.
An archived copy of the previous programme terms is available for reference. It is not a current reward offer.
Scope
We accept reports about Willed-owned applications at:
- willed.com.au and www.willed.com.au
- app.willed.com.au
- Willed-controlled API and Firebase-backed application workflows reachable from those applications
This does not authorise testing other subdomains, third-party systems or the underlying infrastructure of our service providers. Please obtain written approval before actively testing production systems or running automated scans. Reporting an issue encountered during normal use does not require prior approval.
Submission guidelines
Send your report to security@willed.com.au with the subject line ‘Security Vulnerability Report’. The previous ‘Bug Bounty Submission’ subject line is also accepted. Include:
- The affected application, URL or workflow
- The preconditions, observed behaviour and concrete security impact
- Minimal, safe steps to reproduce the issue
- Relevant screenshots or a proof of concept with sensitive data removed
- Your contact information for follow-up communication
We assess reports on their evidence and impact, not whether AI tools were used. Verify your claims before submitting them. Do not include customer data, credentials or secrets, or upload them to third-party AI services. We do not require harmful exploitation or additional access to demonstrate an issue. We will triage reports and coordinate follow-up based on risk.
Rules of engagement
Use only accounts and synthetic data specifically authorised for testing. Do not access, modify, delete or extract other users’ data. Do not disrupt availability, perform denial-of-service or load tests, use social engineering or physical attacks, establish persistence, or move into other accounts or systems.
Stop testing and report promptly if you encounter personal information, an authentication bypass or another user’s account. Do not continue to prove the impact, and stop whenever we ask you to. Keep findings confidential while we investigate and coordinate remediation and any public disclosure with you.
Good-faith reporting and safe harbour
We will not initiate legal action or make a complaint to law enforcement for security research conducted in good faith, within the scope of this policy and any written testing authorisation, and in accordance with these rules. Accidental discovery followed by prompt stopping and reporting in good faith does not by itself disqualify you from this commitment. It is not conditional on a reward or on being the first person to report an issue.
This commitment does not cover deliberate harmful activity or continued testing after a stop instruction. It applies only to Willed’s own actions; we cannot authorise access to third-party systems or bind third parties or law enforcement.
Privately commissioned testing
Paid testing must be agreed separately in writing before work begins. Each engagement must specify the authorised targets, accounts, methods, testing window, fixed fee or total reward budget, deliverables and retesting arrangements. Sending an unsolicited report does not create a paid engagement or authorise further testing.
Contact
For any questions or concerns, please contact our security team at security@willed.com.au.
Acknowledgements
We appreciate the efforts of all security researchers who contribute to making our platform more secure.