Back to Help Centre

Responsible Disclosure

Last Updated: 24 August 2026
5 min read

Found a security issue? Tell us.

Security reports for iDecide are received and triaged by the HLD Group security team. Email us and you will get a human response — we do not use automated ticket bots for vulnerability reports.

security@hldgroup.org

1. Our Commitment

People trust iDecide with wills, health directives, financial records and the details of their digital lives. Protecting that information is the whole job, and we know that no amount of internal testing catches everything.

We welcome reports from security researchers, customers and members of the public. If you have found a vulnerability in an iDecide product or service, we want to hear about it — and we commit to investigating it, keeping you informed, and fixing what needs fixing.

2. Who Handles Reports (HLD Group)

Vulnerability reports for iDecide are handled by the HLD Group security team, which is responsible for security engineering, vulnerability management and incident response across the group's products, including iDecide.

Centralising this in one team means reports are triaged by people who know the infrastructure, and that a single report reaches everyone who needs to act on it.

Security contact: security@hldgroup.org

Handled by: HLD Group Security Team

Preferred languages: English

Machine-readable policy: /.well-known/security.txt (RFC 9116)

Please use the security address only for vulnerability reports. General privacy, account and support questions are best sent to contact@idecide.co so they reach the right team quickly.

3. Scope

The following are in scope for this policy:

  • The iDecide website and any subdomain of idecide.co
  • The iDecide web application and customer dashboard
  • iDecide mobile applications, where published by us
  • APIs and endpoints that serve the products above
  • Vulnerabilities in our configuration of third-party services that expose iDecide customer data

Issue classes we are particularly interested in include authentication and session flaws, access-control and tenant-isolation failures, injection, remote code execution, server-side request forgery, exposed credentials or secrets, insecure direct object references, and any path that exposes one customer's documents to another party.

4. Out of Scope

The following are generally out of scope. You are still welcome to report them, but they are unlikely to be treated as vulnerabilities:

  • Denial of service, volumetric, brute-force or load-generating testing of any kind
  • Social engineering, phishing or physical attacks against our staff, customers or offices
  • Reports produced solely by automated scanners with no demonstrated impact
  • Missing security headers, cookie flags or TLS configuration nits without a working exploit
  • Self-XSS, clickjacking on pages with no sensitive state change, and missing SPF/DMARC on non-mail domains
  • Vulnerabilities in third-party services we do not control, or in outdated browsers and platforms
  • Publicly known issues in dependencies within a reasonable patch window

5. How to Report

Email security@hldgroup.org with as much detail as you can. A good report usually includes:

  • The affected product, URL, endpoint or IP address
  • A clear description of the vulnerability and why it matters
  • Step-by-step instructions to reproduce it
  • Proof-of-concept code, requests or screenshots where relevant
  • Any accounts, tooling or test data you used
  • How you would like to be credited, if the issue is confirmed

Please send one issue per email, and let us know up front if you believe the vulnerability is being actively exploited or if customer data is already exposed — we will escalate immediately.

Do not include third-party personal data, customer documents or credentials in your report. Describe what you were able to access rather than sending the data itself, and delete any copies once we confirm receipt.

6. What to Expect From Us

When you report a vulnerability under this policy, we will:

Acknowledge within 3 business days

A person from the HLD Group security team confirms we have your report.

Triage within 10 business days

We validate the issue, assess severity and impact, and tell you what we found.

Keep you updated

We provide progress updates at least every 14 days until the issue is resolved or closed.

Remediate on a risk-based timeline

Critical issues are prioritised immediately; lower-severity issues are scheduled into our normal release cycle.

Notify where required

If an issue involves personal information, we follow our incident response and notifiable data breach obligations.

Credit you, if you want it

We are happy to acknowledge researchers publicly once a fix has shipped.

We aim to coordinate any public disclosure with you. Our default request is that you give us 90 days from acknowledgement before publishing details, and we will work with you if a fix needs longer or can be shipped sooner.

7. Rules of Engagement

To stay within this policy, please:

  • Only test against accounts and data that belong to you, or that you have explicit permission to use
  • Stop as soon as you have confirmed a vulnerability — do not pivot further into our systems
  • Never access, modify, delete, exfiltrate or retain another person's data
  • Avoid any action that degrades service for our customers, including automated scanning at volume
  • Do not attempt to social-engineer our staff, contractors or customers
  • Keep the details of the issue confidential until we have had a reasonable chance to fix it
  • Comply with all applicable laws, including the Australian Criminal Code Act 1995 and the Privacy Act 1988

We do not currently operate a paid bug bounty programme, and no monetary reward should be assumed. Reports are never conditional on payment; demands for payment in exchange for withholding a vulnerability are treated as extortion, not research.

8. Safe Harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised. We will not pursue or support legal action against you, and if a third party brings action against you for research conducted under this policy, we will make it known that your activity was authorised.

Safe harbour applies to the scope described above and to conduct that follows the rules of engagement. It does not extend to accessing other people's data, disrupting our services, extortion, or activity that is unlawful regardless of intent.

If you are unsure whether a specific test is permitted, ask us first at security@hldgroup.org. We would much rather answer a question than receive an apology.

9. Recognition

Researchers who report a confirmed, in-scope vulnerability are credited in our security acknowledgements once a fix has shipped — with your name, handle, or anonymously, whichever you prefer. Tell us how you would like to appear when you report.

10. Contact

Vulnerability reports: security@hldgroup.org (HLD Group Security Team)

General enquiries: contact@idecide.co

Response hours: Monday–Friday, 9:00 AM – 5:00 PM AEST (critical reports are escalated outside these hours)