Scope
This policy applies to vulnerabilities in systems, products and services that F Creative Studio 360 owns or operates, including:
- Our website and web applications — fcreativestudio360.com, associated subdomains, contact forms and other sites we publish.
- Platforms we operate — services we run in the delivery of cybersecurity, cloud, software, AI and related work, where those systems are ours to fix.
- APIs and integrations — APIs, webhooks and integration endpoints that we publish or operate.
- Our own infrastructure — networks and cloud environments we operate for our business, not environments that belong to a client.
This policy does not apply to:
- Systems, networks or data belonging to our clients. Those are covered by the relevant engagement agreement.
- Third-party products or services we recommend, resell or connect to, unless the issue is in an instance we operate and can remediate ourselves.
- Configurations or data a client supplied to us for a test, assessment or project.
We will not investigate the following unless you can show a concrete, working impact:
- SSL/TLS observations such as cipher preference or certificate-transparency entries, without a working proof of concept.
- Missing HTTP headers such as CSP, HSTS or X-Frame-Options, without a demonstration of harm.
- Content spoofing, tabnabbing, or disclosure of information that is already public and not sensitive.
- Password autocomplete, clickjacking on pages that do not perform a sensitive action, and self-XSS.
- Rate-limit or account-enumeration notes that do not show an exploitable outcome.
- Social engineering or phishing of our staff, clients or partners.
- Physical access to our offices, people or hardware.
- Denial-of-service testing, unless it exposes a separate flaw we can fix without the availability attack.
- Issues in third-party libraries, unless they affect a system we operate and we can remediate them independently.
If you are unsure whether something is in scope, send it anyway. We would rather review a report that falls outside this policy than miss a real issue.
How to report a vulnerability
If you believe you have found a vulnerability in scope, tell us before you tell anyone else. Do not post it on social media, in a public issue tracker, or through a general support form.
Email security@fcreativestudio360.com with the subject line “Vulnerability report”. If the report includes exploit detail, credentials or other sensitive material, say so in a short first message and we will arrange a more private way to receive it.
Include what you can of the following:
- A clear description of the issue, using a recognised label where you have one (for example OWASP, CWE or a CVSS category): SQL injection, IDOR, SSRF, stored XSS, authentication bypass, privilege escalation.
- The system, product, URL, API endpoint or version affected.
- Steps we can follow to reproduce it reliably.
- Proof that stays benign: screenshots, a short recording, or the HTTP request and response. Do not destroy data or leave a lasting change behind.
- Who or what could be affected if someone else used it: data, systems or users.
- Whether you believe it is being exploited now.
- Your name or handle, and an email address, if you want to be credited. Anonymous reports are accepted.
Researcher guidelines
Please work in good faith. While you are testing:
- Stay inside the systems listed in Scope.
- Avoid anything that interrupts our services or touches a client environment.
- Do not access, change, copy or keep data beyond the minimum needed to show that the issue exists and what it could do.
- Stop as soon as you see personal information, client data or credentials, and tell us straight away.
- Do not publish or share the detail until we have had a reasonable chance to investigate and fix it.
Please do not:
- Social-engineer, phish or impersonate our staff, contractors or clients.
- Test physical security, or try to enter our premises or reach our hardware.
- Run denial-of-service, load tests, or automated scans at a volume that would degrade the service.
- Go further than confirming the issue and understanding its impact.
- Place malware, a backdoor or any other malicious code on our systems.
- Test systems that belong to our clients, even if you can reach them from something of ours.
You must comply with the law that applies to you, including the Criminal Code Act 1995 (Cth) and the Privacy Act 1988 (Cth) where they apply, and the equivalent law in your own country. This policy does not permit anything that is unlawful.
Our commitments
For a report that follows this policy, we will:
- Acknowledge receipt within 2 business days.
- Assess it within 5 business days, including whether it is in scope and a first view of severity.
- Update you while we investigate and fix it, including if our view of severity or timing changes.
- Tell you when it has been fixed or mitigated.
- Credit you by name or handle if we publish an advisory, unless you ask to stay anonymous.
- Not pursue civil or criminal action against you for research done in good faith, inside this policy, and within the scope and guidelines above.
We treat reports as confidential. We will not share your contact details or the technical content of a report with a third party without your consent, except where the law requires it.
There is no payment or reward programme. The times above are what we aim for. A complex report, or a period with many reports, can take longer.
CVE assignment
If a confirmed vulnerability meets the criteria for a CVE identifier under the CVE Programme, we will coordinate assignment as part of public disclosure. Identifiers use the standard form CVE-YYYY-NNNN.
If the issue sits in a third-party product, we will work with that vendor or the relevant CVE Numbering Authority. If you want to be named, we will credit you in the CVE record and in any advisory we publish.
Conduct that falls outside this policy
The commitment not to pursue legal action does not cover research or a report that involves any of the following:
- Accessing, taking, changing or destroying data beyond what is needed to demonstrate the issue.
- Interacting with a client’s systems or data.
- Deliberately disrupting our services.
- A report that is false, fabricated or misleading.
- A demand for payment in exchange for the information or for staying silent.
- Public disclosure before we have had a reasonable chance to respond and remediate.
- Any breach of applicable Australian or other law during the research or the submission.
We may refer that kind of conduct to the Australian Federal Police, the Australian Cyber Security Centre, or another relevant authority.
Client environments
This policy is for unsolicited reports about our own systems. Security testing we perform for a client is governed by that client’s agreement and the agreed scope of work, not by this page.
If you find an issue in a client environment, do not test it further under this policy and do not send it to us as if it were ours. Contact that organisation through its own disclosure channel.
Acknowledgements
We will list researchers here when a valid vulnerability has been reported under this policy and the reporter has asked to be named. There are no public acknowledgements yet.
Contact
- Security reports: security@fcreativestudio360.com
- Other enquiries: Contact
- Location: Melbourne, VIC, Australia
- Response time: 2 business days for vulnerability reports sent to the address above.
Talk to F Creative Studio 360
Send vulnerability reports to security@fcreativestudio360.com. This page describes how we handle those reports. It is not legal advice and it does not authorise unlawful activity.
