1. Purpose
Audentia Nova Pty Ltd ("Audentia", "we", "us") maintains this process so customers, researchers, and partners can report security issues that may affect WebStream software, the customer entitlement Portal, AWS Marketplace fulfilment, or other Audentia-operated services.
2. How to report
Email security@webstream-acp.com with the subject line beginning with [SECURITY].
Do not use the public Support Board for active vulnerability details or exploit material.
3. What to include
Include as much of the following as you can. Incomplete reports are still welcome.
- Your name and a contact email (or organisation security contact)
- Product or service affected (for example: WebStream ACP deployment, Portal, Marketplace fulfilment, website)
- AWS Marketplace customer identifier or Portal account email, if applicable
- Description of the issue or incident, including when you observed it
- Steps to reproduce, proof-of-concept notes, or relevant log excerpts (redact secrets and personal data where possible)
- Impact assessment (confidentiality, integrity, availability) if known
- Whether you believe customer data may be affected
4. Acknowledgement and response
- We aim to acknowledge security reports within 2 business days (Australian Western Standard Time).
- We aim to provide an initial triage status (accepted / needs more info / out of scope) within 5 business days of acknowledgement.
- Remediation timelines depend on severity and deployment model. Critical issues affecting Audentia-operated services are prioritised for patching and customer communication as appropriate.
Business days exclude weekends and Australian public holidays observed in Western Australia.
5. Scope
In scope
- Audentia-operated services: Website, customer entitlement Portal, licence/support APIs, and AWS Marketplace fulfilment paths
- WebStream software defects that could lead to unauthorised access, data exposure, privilege escalation, or remote code execution when deployed as documented
- Security misconfigurations in Audentia-published Marketplace images or templates that are reproducible from our published guidance
Out of scope / customer-operated
- Issues limited to a customer's own infrastructure, IAM, network, certificates, or operating-system hardening outside Audentia's control
- Compromises of customer end-user accounts caused solely by weak passwords, shared credentials, or customer-disabled authentication
- Third-party products or services not provided by Audentia
- Social engineering of Audentia staff without prior written authorisation for a coordinated test
- Denial-of-service volume testing against production services without prior written authorisation
If you are unsure whether an issue is in scope, report it — we will advise.
6. Responsible disclosure
- Give us a reasonable opportunity to investigate and remediate before public disclosure.
- Do not access, modify, or delete data that is not yours.
- Do not use findings to disrupt service availability.
- Do not include live credentials, session tokens, or exploit payloads that could harm other customers in public channels.
Good-faith research conducted within these guidelines will not result in legal action from Audentia solely for the act of reporting.
7. Customer security incidents in your deployment
WebStream is typically deployed in your environment. If you detect a security incident in your deployment (for example, suspicious session activity or policy violations), use your internal incident process and WebStream audit/session tools as appropriate.
If the incident may involve an Audentia product defect, Marketplace fulfilment, or Portal compromise — or if you need Audentia's assistance — email security@webstream-acp.com using the guidance in Section 3.
8. Contact
Audentia Nova Pty Ltd
Office 26, 217 Hay Street, Subiaco, Western Australia 6008
Security: security@webstream-acp.com
Privacy: privacy@webstream-acp.com
Related: Privacy Policy · Security & Compliance · Security documentation