Product: VettiGuard Product owner and provider: Ikemba Tech (ABN 82 565 415 510) Effective date: 25 September 2026 Version: 1.3
1. Security approach
VettiGuard is a trust and verification platform. Security controls are therefore designed around server-side authority, short-lived capabilities, action and origin binding, single-use responses, least privilege, workspace isolation, logging and controlled evidence retention.
2. Customer security responsibilities
Customers are responsible for protecting their own credentials, applications, devices, infrastructure and user accounts. Private VettiGuard secrets must remain on trusted infrastructure and must not be embedded in browser code, public repositories, logs or analytics.
3. Vulnerability reporting
Security researchers and customers should report suspected vulnerabilities privately to support@vettiguard.com with a concise description, affected URL or component, safe reproduction steps and the potential impact.
Do not include production passwords, private keys, unrelated customer data, raw identity documents or biometric evidence in an initial report.
4. Good-faith research conditions
VettiGuard welcomes good-faith security research that:
- uses accounts and data you own or are authorised to test;
- avoids privacy violations and access to other customers' information;
- avoids denial-of-service, destructive actions and resource exhaustion;
- stops after enough evidence is obtained to demonstrate the issue;
- does not use social engineering, physical attacks or malicious persistence;
- gives VettiGuard a reasonable opportunity to investigate and remediate before public disclosure; and
- complies with applicable law.
5. Out-of-scope activity
Testing is not authorised where it involves data exfiltration, credential theft, malware, phishing, brute-force activity against real users, volumetric denial-of-service, destructive payloads, unauthorised third-party systems or accessing another customer's identity evidence.
6. Response and coordination
VettiGuard will seek to acknowledge credible reports, assess severity, reproduce the issue and coordinate remediation. Resolution timing depends on severity, complexity, provider dependencies and the risk of the issue.
VettiGuard may ask for additional safe diagnostic details. Security fixes may be deployed without advance notice where disclosure would materially increase risk.
7. No automatic bounty
This Policy is not a bug-bounty promise. Any reward is discretionary unless a separate published bounty program expressly states otherwise.
8. Security incidents and privacy
A vulnerability report is distinct from a privacy complaint or data-breach notification. If a security issue appears to involve personal information, VettiGuard will assess it under the incident-response and privacy processes as appropriate.