Skip to main content
Back to home
SECURITY · DISCLOSURE POLICY

Vulnerability Disclosure Policy

Version 1.0. Effective 25 July 2026.

1. How to report

Email security@afterservice.ai. Include enough detail for us to reproduce the issue: the affected URL or endpoint, the steps you took, and what you observed. If you have a proof of concept, attach it.

You do not need to ask permission first, and you do not need to be a professional researcher. If you found something by accident, we would still like to hear about it.

2. Our commitments

  • We acknowledge every report within 3 business days.
  • We give you an initial assessment, including whether we consider it in scope and what we intend to do, within 10 business days.
  • We keep you informed while we work on a fix, and we tell you when it is deployed.
  • We are happy to credit you publicly once the issue is resolved, if you want that. We will not name you without your agreement.
  • We do not pay bounties. We would rather say so plainly than leave you guessing.

3. In scope

  • www.afterservice.ai, this public website
  • advocate.afterservice.ai, the AfterService platform
  • Our public API endpoints

4. Out of scope

Reports limited to the following are unlikely to be actioned, though we will still read them:

  • Automated scanner output with no demonstrated impact, and missing hardening headers with no accompanying exploit.
  • Denial of service, volumetric testing, or anything that degrades availability for users. Please do not attempt it. See section 5.
  • Social engineering of our staff, partners or users, and physical attacks.
  • Vulnerabilities in third-party services we do not control.
  • Issues requiring a rooted or jailbroken device, or an already compromised account.

5. Safe harbour

If you make a good-faith effort to comply with this policy while researching and reporting an issue, we will not pursue or support legal action against you in relation to that research, and we will make it known that your access was authorised if a third party raises it.

Good faith means all of the following:

  • You do not access, modify, download or retain anyone else's data. Our users are veterans, serving members and their families, and their information includes health and mental health information. If a vulnerability exposes it, stop, and tell us what you saw without collecting more.
  • You do not degrade, interrupt or deny service to other users, and you do not run volumetric or load testing against our infrastructure.
  • You use only your own test accounts, and you do not attempt to reach accounts that are not yours.
  • You give us a reasonable opportunity to fix the issue before disclosing it publicly. If you intend to publish, tell us your timeline and we will work to it.
  • You comply with applicable Australian law.

This section is not legal advice and does not bind any third party, including our providers. If you are unsure whether something is permitted, ask us first at security@afterservice.ai.

6. If you find user data exposed

Treat it as urgent and stop testing. Email us immediately, tell us what you were able to reach, and do not keep a copy. We are bound by the Notifiable Data Breaches scheme and will handle it under the process in our Privacy Policy at section 9.

7. Machine-readable version

Our contact details are published per RFC 9116 at /.well-known/security.txt.

8. Contact

Security: security@afterservice.ai
Privacy Officer: privacy@afterservice.ai

AfterService Pty Ltd (ABN 21 687 135 048)
Perth, Western Australia

See also our Privacy Policy, Terms and Conditions and Sub-processor List.