Select Page

Responsible Disclosure Policy

At Art Classes Port Macquarie, we take the security of our website and our customers’ information seriously. If you believe you’ve found a security vulnerability on artclassesportmacquarie.com.au, we appreciate you letting us know so we can investigate and address it promptly.

How to report a vulnerability

Please email us at info@artclassesportmacquarie.com.au with the subject line: “Responsible Disclosure – Security Report”.

Include as much detail as possible, such as:

  • The affected URL(s) or page(s)
  • A clear description of the issue and the potential impact
  • Step-by-step instructions to reproduce (where possible)
  • Screenshots or screen recordings (if helpful)
  • Any proof-of-concept details that demonstrate the issue safely
  • Your contact details for follow-up questions

Guidelines for testing

We ask that you:

  • Act in good faith and avoid privacy violations, data destruction, or service disruption
  • Only access your own accounts/data (or data you have explicit permission to access)
  • Stop testing once you’ve confirmed the vulnerability
  • Give us a reasonable opportunity to fix the issue before sharing it publicly

Please do not

To protect our customers and systems, please do not:

  • Perform denial-of-service (DoS/DDoS) testing
  • Use automated scanning that significantly impacts site performance
  • Attempt social engineering (phishing, phone calls, staff impersonation, etc.)
  • Attempt physical security breaches
  • Exfiltrate, modify, or delete data
  • Demand payment or threaten to disclose vulnerabilities (this will be treated as malicious)

What you can expect from us

When you report an issue responsibly, we will:

  • Confirm receipt of your report
  • Investigate and prioritise the issue based on risk
  • Work to remediate the vulnerability as appropriate
  • Keep you informed where practical

If you would like to be credited for your report, please tell us the name/handle you’d like us to use (optional).

Safe harbour

We will not pursue legal action against researchers who:

  • Follow this policy,
  • Make a good-faith effort to avoid harm, and
  • Do not access or expose customer data beyond what is necessary to demonstrate the issue.

This safe harbour does not apply to activities that are illegal, malicious, or outside the scope of this policy.

Scope

This policy applies to artclassesportmacquarie.com.au and pages directly served by our website. Reports relating to third-party services (e.g., payment providers, embedded tools, or external platforms) may need to be reported to those providers directly, though we’ll help route the report if we can.

Thank you

We appreciate the security community and anyone who helps keep our website safe for our customers.