APRA · Vulnerability Disclosure

Apra Vulnerability Disclosure

Vulnerability disclosure

APRA runs a coordinated vulnerability disclosure program on Bugcrowd. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

InsuranceAustraliaRegulatorPrudential RegulationGeneral InsuranceLife InsurancePrivate Health InsuranceRegulatory ReportingMarket InfrastructureRisk DataSuperannuationBanking
Program: Bugcrowd security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://bugcrowd.com/engagements/apra-vdp-pro

Source

Vulnerability Disclosure

apra-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-25'
method: searched
probe: true
source: https://www.apra.gov.au/.well-known/security.txt
docs: https://www.apra.gov.au/security
policy:
- https://www.apra.gov.au/security
contact:
- https://bugcrowd.com/engagements/apra-vdp-pro
program:
  name: APRA Vulnerability Disclosure Program
  platform: Bugcrowd
  url: https://bugcrowd.com/engagements/apra-vdp-pro
  status: 200
  type: vulnerability-disclosure
  bounty: false
  bounty_note: APRA states it cannot financially compensate researchers; with consent
    it will publish a researcher's name or alias as recognition.
  safe_harbor: false
  safe_harbor_note: The program explicitly does NOT authorise security testing against
    APRA systems — it is a report-what-you-find channel, not an authorised testing
    programme.
  preferred_languages: en
scope:
  in_scope:
  - Any product, system or service wholly belonging to APRA that the reporter is authorised
    to use or has lawful access to
  - Any product, service or infrastructure APRA provides to shared service partners
    that the reporter is authorised to use
  - Third-party owned services used as part of APRA services that the reporter is authorised
    to access
  prohibited:
  - Public disclosure of vulnerabilities in APRA systems
  - Physical testing of government facilities
  - Social engineering of employees, contractors or third parties
  - Resource-exhaustion attacks (DoS / DDoS)
  - Automated vulnerability assessment tools
  - Introducing malicious software
  - Reverse engineering APRA products or systems
  - Modifying, destroying, exfiltrating or retaining APRA-stored data
  - Accessing accounts or data not belonging to the reporter
report_contents:
- Version of the website or supporting product containing the vulnerability
- System/environment where the issue was reproduced (browser, OS)
- Vulnerability type or classification (RCE, XSS, CWE)
- Step-by-step reproduction instructions
- Proof-of-concept or exploit code
- Potential impact
- Names of any test accounts created
- Date the vulnerability was identified
- Reporter contact details
related:
  service_desk: support@apra.gov.au
  data_team: dataanalytics@apra.gov.au
  penetration_testing_note: >-
    APRA has publicly disclosed acting on its own penetration testing: the legacy
    Direct to APRA (D2A) submission client was taken offline after a routine
    penetration test identified vulnerabilities — see lifecycle/apra-lifecycle.yml.
evidence:
- source: https://www.apra.gov.au/.well-known/security.txt
  kind: security.txt (RFC 9116, live probe 2026-07-25, HTTP 200)
- source: https://www.apra.gov.au/security
  kind: published vulnerability disclosure policy page (HTTP 200)
- source: https://bugcrowd.com/engagements/apra-vdp-pro
  kind: >-
    Bugcrowd engagement page (HTTP 200, titled "Vulnerability Disclosure - APRA
    Vulnerability Disclosure Engagement")