Security posture, without the theatre
The public deployment is configured to favour HTTPS, restrict access to common secret and source-file paths, send browser security headers, limit framing, and allow YouTube only through declared frame sources. Those controls reduce particular risks; they do not make an application invulnerable. Authentication, authorisation, dependency management, backup recovery, logging and incident response require continuing operational review as production functions are enabled.
Report a potential vulnerability
Email security@dopetech.au. Start with a concise description and do not include passwords, access tokens, personal data or weaponised code in the first message. We can agree on a safer transfer method if sensitive evidence is necessary.
A useful report includes:
- the affected URL, feature and account role;
- reproducible steps and the observed versus expected result;
- likely impact and any conditions required for exploitation;
- a minimal proof using accounts and data you are authorised to access;
- your preferred name for acknowledgement, or a request to remain anonymous.
The machine-readable contact is at /.well-known/security.txt. Please verify that the security mailbox is operational before relying on it for a production launch.
Scope and priority
The intended scope is the DopeTech-owned production website at dopetech.au and first-party subdomains explicitly identifying this policy. High-value reports include unauthorised access to accounts or unpublished content, privilege escalation, injection, server-side request forgery, exploitable cross-site scripting, sensitive data exposure and security-control bypass.
Third-party retailer sites, YouTube, hosting-provider infrastructure, social networks and vendor services are outside our authority. Report their issues to the relevant owner. The following usually do not qualify without demonstrated impact: automated version-only findings, missing “best practice” headers, self-XSS, logout CSRF, email spoofing observations without an exploitable configuration, rate-limit suggestions, clickjacking on pages with no sensitive action, and denial-of-service capacity claims.
Authorised testing rules
- Use only your own test accounts and the minimum requests needed to prove the issue.
- Stop immediately if you encounter another person’s data, credentials or non-public business information; record only what is needed to identify the exposure.
- Do not use denial of service, destructive payloads, persistence, malware, spam, phishing, social engineering or physical intrusion.
- Do not alter data you did not create, access messages belonging to others, download data in bulk, or pivot into another system.
- Do not run high-volume automated scanners against production without written approval.
- Give reasonable time for investigation and remediation before public disclosure. Coordinate timing where users could remain at risk.
This policy does not authorise testing of third-party assets, violation of law, or access beyond what is necessary to demonstrate an issue.
What happens after a report
Acknowledge
Target: within five business days, with a reference or request for the missing detail needed to reproduce.
Triage
Validate scope and impact, preserve relevant records and assign a risk-based priority.
Remediate
Contain where needed, develop and verify a correction, and assess related paths and affected people.
Close
Share a status summary when practical and agree on acknowledgement or coordinated publication.
Response targets are goals, not contractual service levels or a bug bounty promise. Complex, third-party or disputed reports can take longer. DopeTech does not currently advertise a cash reward program.
Good-faith research
If you make a genuine effort to follow this policy, avoid privacy and operational harm, and promptly report what you find, DopeTech’s policy is to treat that work as authorised for purposes of our own access controls and not initiate legal action over the research. If a concern arises, contact us before continuing.
This commitment cannot bind third parties or protect unlawful conduct, and it does not waive rights of people whose data or systems are affected. Accidental overreach should be disclosed immediately and the affected data deleted after we confirm what must be retained for investigation.
Enterprise security information
Prospective business customers can request current architecture boundaries, subprocessors, data-flow details, recovery objectives, vulnerability-management practices and independent assessment material that actually exists. Sensitive information may require a confidentiality agreement. Answers are scoped to the named service version and should not be inferred from a marketing page.
Security questionnaires can be sent to security@dopetech.au. A signed enterprise agreement, where applicable, defines incident notification and service commitments.
Compromised account or privacy incident?
For an immediate account concern, change reusable credentials at their original provider and contact security@dopetech.au with “Account security” in the subject. For a privacy-rights request without a security issue, use privacy@dopetech.au. Do not publish exploit details or personal information in a community post.