Security reports for iDecide are received and triaged by the HLD Group security team. Email us and you will get a human response — we do not use automated ticket bots for vulnerability reports.
security@hldgroup.orgPeople trust iDecide with wills, health directives, financial records and the details of their digital lives. Protecting that information is the whole job, and we know that no amount of internal testing catches everything.
We welcome reports from security researchers, customers and members of the public. If you have found a vulnerability in an iDecide product or service, we want to hear about it — and we commit to investigating it, keeping you informed, and fixing what needs fixing.
Vulnerability reports for iDecide are handled by the HLD Group security team, which is responsible for security engineering, vulnerability management and incident response across the group's products, including iDecide.
Centralising this in one team means reports are triaged by people who know the infrastructure, and that a single report reaches everyone who needs to act on it.
Security contact: security@hldgroup.org
Handled by: HLD Group Security Team
Preferred languages: English
Machine-readable policy: /.well-known/security.txt (RFC 9116)
Please use the security address only for vulnerability reports. General privacy, account and support questions are best sent to contact@idecide.co so they reach the right team quickly.
The following are in scope for this policy:
Issue classes we are particularly interested in include authentication and session flaws, access-control and tenant-isolation failures, injection, remote code execution, server-side request forgery, exposed credentials or secrets, insecure direct object references, and any path that exposes one customer's documents to another party.
The following are generally out of scope. You are still welcome to report them, but they are unlikely to be treated as vulnerabilities:
Email security@hldgroup.org with as much detail as you can. A good report usually includes:
Please send one issue per email, and let us know up front if you believe the vulnerability is being actively exploited or if customer data is already exposed — we will escalate immediately.
Do not include third-party personal data, customer documents or credentials in your report. Describe what you were able to access rather than sending the data itself, and delete any copies once we confirm receipt.
When you report a vulnerability under this policy, we will:
A person from the HLD Group security team confirms we have your report.
We validate the issue, assess severity and impact, and tell you what we found.
We provide progress updates at least every 14 days until the issue is resolved or closed.
Critical issues are prioritised immediately; lower-severity issues are scheduled into our normal release cycle.
If an issue involves personal information, we follow our incident response and notifiable data breach obligations.
We are happy to acknowledge researchers publicly once a fix has shipped.
We aim to coordinate any public disclosure with you. Our default request is that you give us 90 days from acknowledgement before publishing details, and we will work with you if a fix needs longer or can be shipped sooner.
To stay within this policy, please:
We do not currently operate a paid bug bounty programme, and no monetary reward should be assumed. Reports are never conditional on payment; demands for payment in exchange for withholding a vulnerability are treated as extortion, not research.
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised. We will not pursue or support legal action against you, and if a third party brings action against you for research conducted under this policy, we will make it known that your activity was authorised.
Safe harbour applies to the scope described above and to conduct that follows the rules of engagement. It does not extend to accessing other people's data, disrupting our services, extortion, or activity that is unlawful regardless of intent.
If you are unsure whether a specific test is permitted, ask us first at security@hldgroup.org. We would much rather answer a question than receive an apology.
Researchers who report a confirmed, in-scope vulnerability are credited in our security acknowledgements once a fix has shipped — with your name, handle, or anonymously, whichever you prefer. Tell us how you would like to appear when you report.
Vulnerability reports: security@hldgroup.org (HLD Group Security Team)
General enquiries: contact@idecide.co
Response hours: Monday–Friday, 9:00 AM – 5:00 PM AEST (critical reports are escalated outside these hours)