generated: '2026-07-25' method: searched probe: true source: https://www.apra.gov.au/.well-known/security.txt docs: https://www.apra.gov.au/security policy: - https://www.apra.gov.au/security contact: - https://bugcrowd.com/engagements/apra-vdp-pro program: name: APRA Vulnerability Disclosure Program platform: Bugcrowd url: https://bugcrowd.com/engagements/apra-vdp-pro status: 200 type: vulnerability-disclosure bounty: false bounty_note: APRA states it cannot financially compensate researchers; with consent it will publish a researcher's name or alias as recognition. safe_harbor: false safe_harbor_note: The program explicitly does NOT authorise security testing against APRA systems — it is a report-what-you-find channel, not an authorised testing programme. preferred_languages: en scope: in_scope: - Any product, system or service wholly belonging to APRA that the reporter is authorised to use or has lawful access to - Any product, service or infrastructure APRA provides to shared service partners that the reporter is authorised to use - Third-party owned services used as part of APRA services that the reporter is authorised to access prohibited: - Public disclosure of vulnerabilities in APRA systems - Physical testing of government facilities - Social engineering of employees, contractors or third parties - Resource-exhaustion attacks (DoS / DDoS) - Automated vulnerability assessment tools - Introducing malicious software - Reverse engineering APRA products or systems - Modifying, destroying, exfiltrating or retaining APRA-stored data - Accessing accounts or data not belonging to the reporter report_contents: - Version of the website or supporting product containing the vulnerability - System/environment where the issue was reproduced (browser, OS) - Vulnerability type or classification (RCE, XSS, CWE) - Step-by-step reproduction instructions - Proof-of-concept or exploit code - Potential impact - Names of any test accounts created - Date the vulnerability was identified - Reporter contact details related: service_desk: support@apra.gov.au data_team: dataanalytics@apra.gov.au penetration_testing_note: >- APRA has publicly disclosed acting on its own penetration testing: the legacy Direct to APRA (D2A) submission client was taken offline after a routine penetration test identified vulnerabilities — see lifecycle/apra-lifecycle.yml. evidence: - source: https://www.apra.gov.au/.well-known/security.txt kind: security.txt (RFC 9116, live probe 2026-07-25, HTTP 200) - source: https://www.apra.gov.au/security kind: published vulnerability disclosure policy page (HTTP 200) - source: https://bugcrowd.com/engagements/apra-vdp-pro kind: >- Bugcrowd engagement page (HTTP 200, titled "Vulnerability Disclosure - APRA Vulnerability Disclosure Engagement")