Security should be inspectable.
CSA treats security as an operating obligation. This page establishes the public reporting channel and the boundaries for good-faith vulnerability disclosure concerning cs-agency.com.au.
Security commitment
CSA applies layered controls to its digital headquarters, including transport security, restrictive browser security headers, least-privilege administration, change control, dependency and secret review, deployment rollback, logging and incident-response processes appropriate to the service.
Responsible disclosure
If you believe you have identified a vulnerability affecting cs-agency.com.au, report it to info@cs-agency.com.au with the subject “Security report”. Include enough information to reproduce and understand the issue, including the affected URL or component, observed behaviour, steps to reproduce and potential impact.
Good-faith testing boundaries
Do not access, alter, delete or exfiltrate data that is not yours; do not perform denial-of-service activity; do not use social engineering; do not deploy malware; do not attempt persistence; and stop testing if you encounter sensitive information or evidence that continued activity could cause harm. Testing must remain limited to assets clearly owned or operated by CSA and within the scope of this public website unless separate written authorisation exists.
What to expect
CSA will aim to acknowledge credible reports, triage them according to severity and scope, preserve relevant evidence and coordinate remediation. Submission of a report does not create an entitlement to payment, public recognition or a commercial relationship unless CSA expressly agrees otherwise.
Security metadata
A machine-readable disclosure contact is published at /.well-known/security.txt. Security-related platform or assurance statements remain evidence-scoped through the Trust Centre.
Contact
info@cs-agency.com.au
Cyber Security Agency Australia Pty Ltd