OUTPACE

Security

Security

Last updated

Outpace intends to sponsor infrastructure that regulated customers will depend on. It would be inconsistent to bring less care to its own website than it expects from a project. This page describes the controls that apply to this website and to the information you send through it. It describes what is in place today, not what is planned.

The website

  • The website is served only over HTTPS, with modern TLS, from a managed hosting platform that handles patching of the serving infrastructure.
  • The site is generated from its source code. There is no content management system, no database behind the pages and no administrative login on the public website.
  • The source code is held in a private repository. Every change is reviewed, passes automated checks, and is deployed through a staging environment before production.
  • Dependencies are reviewed on a schedule and updated when a security advisory applies.

The contact form

  • Enquiries are validated on the server and limited per connection to stop automated submission. Suspected automated submissions are discarded, and the reason is logged by category, never the content.
  • Enquiries are delivered by email through an email delivery service over encrypted connections. They are not stored in a database on the website.
  • The website holds no credentials for your systems and asks for none.

Information handling

Information you send is treated as confidential and is accessible only to the people at Outpace who need it to respond. Access to the systems that hold it requires multi-factor authentication. Information is retained as described in the Privacy policy.

Incidents

If Outpace becomes aware of an incident that may have affected information you sent through this website, it will tell you without undue delay and will meet its obligations under the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth).

Reporting a vulnerability

If you find a security weakness in this website, please report it through the contact form, choosing the general enquiries pathway, with enough detail to reproduce it. Outpace acknowledges reports within two business days. Outpace does not run a bug bounty. Researchers who act in good faith, avoid privacy violations and service disruption, and give Outpace reasonable time to respond will not face legal action from Outpace.