We are planning some website maintenance on Thursday 23 July, from 5:10 pm until 8:00 pm. You may experience some issues with tools and forms. You may also experience issues on the app, or application tracker during this time. If you are a Keystart broker, the loan app will not be available during this time. We apologise for any inconvenience caused.
Keystart is committed to ensuring the security of its customers and employees by protecting their information. This policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preference in how to submit any discovered vulnerabilities.
This policy describes what systems and types of research are covered under this policy, how to send us vulnerability reports, and what you can expect from us.
If you make a good faith effort to comply with this policy during your security research, we will not take any legal action against you.
We will not compensate you for finding potential or confirmed vulnerabilities.
What this policy covers
In scope: This policy applies to the following systems and services:
Out of scope: websites and APIs hosted on other subdomains or with (Cloud) providers are not in scope and not authorised for testing.
Keystart mobile app(s), available at Apple App Store and Google Play Store.
Out of scope
Systems not listed above, including any third-party services or integrations, are excluded from scope, and not authorised for testing. If you aren’t sure whether a system is in scope, please contact Keystart at infosec@keystart.com.au to discuss.
The following activities are out of scope and not permitted against any system:
denial of service (DoS/DDoS) and spam.
social engineering (e.g. phishing) against staff.
physical access attacks (e.g. attempting to access buildings).
uploading malware, backdoors, webshells, or other “weaponised” exploits that could degrade system security or affect other users.
attempts to access or manipulate accounts that do not belong to you (e.g. resetting passwords for other users).
any attempts to modify or destroy data.
In general, low severity issues without a direct security impact (weak SSL cipher suites, missing HTTP security headers, SPF/DKIM/DMARC misconfigurations, etc.) will not be considered in scope.