Security Policy

At LeaveLens, we take the security of our systems and users' data very seriously. Our security policies are designed to protect against unauthorised access, disclosure, alteration, and destruction of data.

Reporting a Vulnerability

If you discover a vulnerability, please contact us immediately at security@vman.com.au. We are committed to working with the security community to verify, reproduce, and respond to legitimate reported vulnerabilities. Once a vulnerability report is received, we will acknowledge the receipt within 24 hours and strive to resolve the issue promptly.

Encryption

We use encryption to protect sensitive information both in transit and at rest. You can find our PGP public key here. We encourage you to use this key to encrypt sensitive information sent to us to ensure it remains confidential. Our encryption practices ensure that data such as vulnerability reports and sensitive communications are protected from unauthorised access.

Preferred Languages

We prefer to receive vulnerability reports in English. This helps ensure that our team can understand and respond to the report as quickly and effectively as possible.

Security Practices

We follow industry best practices to ensure the security of our systems and data. This includes regular security audits, patch management, and employing security measures such as firewalls, intrusion detection systems, and regular vulnerability assessments.

User Responsibility

Users of our services are encouraged to follow security best practices, such as using strong, unique passwords and two-factor authentication. If you suspect your account has been compromised, please contact us immediately.