Responsible Disclosure Policy

Updated: September 2026 · Vpply Pty Limited (ABN 47 636 491 588)

1. About this policy

We want Vpply Interview to be safe for the employers and candidates who use it. If you believe you have found a security vulnerability in our website or platform, we would like to hear from you. This policy explains how to report it, what we will do in return, and the rules we ask you to follow while you look.

2. How to report a vulnerability

Email our security team at security@vpply.com. Please send security reports there rather than to our sales or support contacts, social media or public forums.

To help us understand and fix the issue quickly, please include:

We don't currently offer encrypted email. If your report would need to include sensitive details, such as someone else's personal information, send us a description without them first and we will agree a safer way to share the rest.

3. What we commit to

When you report a vulnerability in line with this policy, we will:

We don't run a bug bounty programme and don't offer payment or rewards for reports.

4. Scope

In scope

Out of scope

If you are unsure whether something is in scope, email us before you test it.

5. Rules for testing

While researching, please:

6. Safe harbour

If you make a good-faith effort to follow this policy, we will not take legal action against you in relation to your research.

This policy can only authorise testing of systems Vpply controls. It does not cover the third-party services listed as out of scope, and it does not cover research that breaks the rules above.

7. Changes to this policy

We may update this policy from time to time. The current version will always be available at this page, and the date at the top shows when it was last updated. A machine-readable pointer to it is published at vpply.com/.well-known/security.txt.