Responsible Disclosure Policy

Ensuring security through responsible reporting.

1. Introduction

At SkillSociety, security is a top priority. We encourage responsible disclosure of security vulnerabilities to protect our users and systems.

2. Scope

This policy applies to all SkillSociety applications, systems, and infrastructure, including our web platform, APIs, and cloud-hosted services.

Out of Scope: Social engineering attacks, denial of service (DoS) testing, and physical security vulnerabilities.

3. How to Report a Vulnerability

To report a security vulnerability, email security@skillsociety.com.au with a description, proof-of-concept, and expected impact.

For secure communication, use our PGP key available at https://skillsociety.com.au/pgp-key.txt.

4. Our Commitment

We acknowledge reports within 2 business days and provide updates within 7 days.

We will not take legal action against researchers following responsible disclosure guidelines.

5. Guidelines for Ethical Testing

Only test on your own accounts and do not access other users' data.

Do not publicly disclose vulnerabilities before a fix is implemented.

Do not engage in activities that disrupt SkillSociety services.

6. Recognition and Incentives

SkillSociety does not currently offer a bug bounty program but may recognize researchers in our Hall of Fame for valuable reports.

7. Legal Safe Harbor

SkillSociety will not take legal action against researchers who follow this policy in good faith.

Adequate time must be provided for remediation before public disclosure.

8. Contact Information

For any security concerns or vulnerability reports, contact security@skillsociety.com.au.

Set the new standard

Expand your hiring capacity today
Icon

Free Trial

Icon

No Lock-in Contracts

Lets Talk

4.9 / 5 Rating
From over 17 Customer & Candidate Reviews