Security

Last reviewed: 1 September 2026

Arterion Pty Ltd welcomes reports from security researchers who help us protect Find a Conference and its users.

Security overview

We use encryption in transit, restrict privileged access to authorised personnel, maintain dependencies, and monitor security-relevant service activity. We triage security reports and handle them according to their severity.

Report a vulnerability

Send reports to security@findaconference.net. Include the affected URL or system, a clear description of the issue and its impact, reproduction steps, and minimal proof of concept where appropriate. Please do not include personal data, credentials, or live secrets in your initial report.

Reports should describe a plausible security impact. We may still review unusual reports that do not fit this guidance.

Scope

This policy covers services controlled by Arterion Pty Ltd under *.findaconference.net. It does not authorise testing of third-party services or any system not controlled by Arterion Pty Ltd.

Responsible testing rules

Test only accounts and data you control. Low-impact automated scanning is allowed when it does not degrade our services.

Do not:

  • Access, modify, copy, or delete data that does not belong to you.
  • Disrupt services, perform denial-of-service testing, or generate excessive traffic.
  • Use social engineering, phishing, spam, credential stuffing, or brute-force attacks.
  • Use destructive payloads or test third-party systems.

Accidental data access

If you encounter another person's data or credentials, stop testing immediately. Do not access or copy additional information, report the exposure to us, securely delete any material you retained, and follow our reasonable handling instructions.

Safe harbour

If you follow this policy, act in good faith, and avoid harm, Arterion Pty Ltd considers your research authorised for the systems within scope. We will not pursue legal action for compliant security research and will work with you to clarify any misunderstanding. We cannot authorise testing of, or make commitments for, third parties.

Coordinated disclosure

We will respond as soon as reasonably practical and ask that you give us a reasonable opportunity to investigate and address a report before public disclosure. We will coordinate a public disclosure date with you by mutual agreement.

We do not offer a bug bounty. With your consent, we may acknowledge valid reports publicly.

Security contact

For security reports, contact security@findaconference.net. For anything else, contact support@findaconference.net.