Skip to content
aicial
Legal

Security and Vulnerability Disclosure Policy

Version: 1.0

Effective date: 19 August 2026

Last reviewed: 19 August 2026

This Security and Vulnerability Disclosure Policy explains our approach to security at a high level, how to report a suspected vulnerability in aicial’s website or services, and what a good-faith security researcher can expect from us in response.

1. About this policy

Aperim Pty Ltd (ABN 46150699737; ACN 150699737) is incorporated in New South Wales, Australia and operates the aicial brand. In this policy, “aicial” refers to that brand; “we”, “us” and “our” refer to Aperim Pty Ltd; and “you” refers to anyone reading or applying this policy, including a security researcher who reports a suspected vulnerability to us.

This policy applies to our website, waitlist and services, and to the aicial-operated systems and configuration we use to provide them — not to the underlying Cloudflare network and platform itself, which Cloudflare operates and secures independently (see section 2). It sets out our approach to security at a high level, explains how to report a suspected vulnerability and what protection a good-faith security researcher receives, and describes what to expect from us in response. No system is completely secure, and nothing in this policy warrants that our services are free of vulnerabilities.

2. Our approach to security

aicial’s infrastructure is entirely Cloudflare-native: Cloudflare Workers for compute, Cloudflare D1 as our database, Cloudflare Turnstile for bot and abuse protection on forms, and Cloudflare’s own Email Service for transactional email. We do not operate our own data centres or servers. Cloudflare’s global network provides the underlying infrastructure and its own network-level protections, and its geographic distribution gives our services a degree of resilience that a single facility could not offer.

Within that infrastructure, we apply the principle of least privilege to internal access: access to production systems and customer data is limited to what a given role genuinely needs, and is not granted by default. The Privacy Policy describes the technical and organisational measures we apply, including access controls, authentication and secrets management, encryption, logging and monitoring, and incident-response procedures, in further detail.

3. Reporting a vulnerability

We use a coordinated disclosure process. If you believe you have found a security vulnerability affecting aicial’s website, services, or the systems we use to provide them, report it to security@aicial.com rather than disclosing it publicly. Please include enough detail for us to reproduce and assess the issue, including the affected system or URL, the steps you followed, and the impact you believe it has.

We ask that you give us reasonable time to investigate and remediate a reported vulnerability before disclosing it publicly. As a guideline, not a fixed deadline, we ask for 90 days from your report, consistent with common industry practice. Some issues take longer to fix properly than others; where we need more time, we will tell you why and keep you updated on our progress.

4. Machine-readable disclosure

Our security contact details, and a pointer back to this policy, are also published in machine-readable form at /.well-known/security.txt, in accordance with RFC 9116 (A File Format to Aid in Security Vulnerability Disclosure). If the two ever appear to conflict, this policy governs.

5. Scope

This policy covers security research and vulnerability reports concerning systems aicial itself operates: our website, our waitlist, our services, and the aicial-operated systems and configuration we use to provide them. It does not cover the underlying Cloudflare network and platform itself, which Cloudflare operates independently of aicial (see section 2).

The following are out of scope under this policy:

  • denial-of-service or distributed denial-of-service testing;
  • physical security testing of any premises;
  • social engineering, phishing or similar testing directed at our staff, contractors or customers;
  • testing directed at a third-party social platform that a customer connects to aicial; and
  • testing directed at Cloudflare’s own network or platform, rather than at the aicial-operated configuration described above.

A connected third-party platform runs its own security program, and a report concerning it should go to that platform, not to us. The same is true of Cloudflare’s network and platform: Cloudflare operates its own, independent vulnerability disclosure process, and a report concerning Cloudflare’s infrastructure itself should go to Cloudflare, not to us.

6. Safe harbour for good-faith research

Our Acceptable Use Policy requires prior written authorisation from security@aicial.com before conducting penetration testing, vulnerability scanning or other security testing against aicial’s systems, network or infrastructure. Good-faith security research conducted in accordance with this policy — including the scope above and the conditions below — satisfies that requirement, and you do not need to separately request authorisation before beginning it.

We will not bring a legal claim against you, and will not report you to law enforcement, in connection with good-faith security research conducted consistently with this policy. To qualify, you must:

  • access, use or store no more data than is reasonably necessary to demonstrate the vulnerability;
  • avoid disrupting or degrading our services;
  • not socially engineer, phish or otherwise attempt to manipulate our staff, contractors or customers;
  • test only systems aicial itself operates, and not Cloudflare’s own network or platform, or a customer’s connected third-party platform accounts, consistent with the scope described above; and
  • report a suspected vulnerability to us promptly and give us reasonable time to remediate it, as described above, before any public disclosure.

This safe harbour describes our own response to your research. It does not bind an independent third party, such as Cloudflare, a connected social platform or another customer, and does not excuse a breach of that third party’s own terms.

7. Acknowledgement and response

We aim to acknowledge a good-faith vulnerability report within 5 business days, and to keep you reasonably informed of our progress toward remediation. Response and remediation times vary with the severity and complexity of the issue.

We do not currently offer a paid bug bounty program. This policy describes the acknowledgement, process and legal protection we offer a good-faith security researcher; it is not an offer of payment or other reward.

8. Changes to this policy

We may update this policy to reflect changes to our services, practices or legal obligations. The version, effective date and last-reviewed date shown at the top identify the current policy. We publish the updated policy on our website and, where a change is material, provide additional notice through the service or by email before it takes effect.

9. Contact us

To report a suspected security vulnerability, or for any other question about this policy, contact:

Aperim Pty Ltd, which operates the aicial brand
ABN 46150699737
ACN 150699737
New South Wales, Australia
Email: security@aicial.com