Security / responsible disclosure

Security Policy

AES Tech is a static content site operated by Australian Enterprise Services. This page explains the controls we publish, the reports we can act on, and how to contact us safely.

Last updated 2026-06-21

Security headers shield showing HTTPS, HSTS, nosniff, frame protection, referrer policy and security.txt.
Security hardening / 12 KB WebP

Static export

The public site is exported as static files, reducing server-side application surface area.

HTTPS only

The live site redirects to the canonical HTTPS host and ships transport security headers.

Browser hardening

Headers cover content type sniffing, frame embedding, referrer policy, permissions policy, and CSP.

Machine-readable policy

Security contacts are published at /.well-known/security.txt and /security.txt.

If you find a security issue affecting the site, please report it responsibly and give us enough detail to reproduce and understand the impact.

Report a vulnerability

  • Email: hello@aestech.com.au
  • Use the subject line: Security report for aestech.com.au.
  • Include the affected URL, steps to reproduce, impact, and any safe proof of concept.
  • Do not access, modify, delete, or exfiltrate data that is not yours.
  • Do not run destructive testing, denial-of-service testing, spam, social engineering, or physical attacks.

What to expect

We acknowledge practical security reports and prioritise fixes based on likely reader impact, exploitability, and exposure. This is not a paid bug bounty program.

For the machine-readable policy, see security.txt.

Scope guide

Useful reports are specific

In scope

Public pages, static assets, headers, redirects, security.txt, and accidental exposure on aestech.com.au.

Out of scope

Denial-of-service tests, spam, social engineering, physical attacks, vendor systems, and destructive testing.

Include

Affected URL, steps to reproduce, observed impact, browser or tool details, and a safe proof of concept where useful.

Response

Practical reports are triaged by risk. This is a responsible disclosure channel, not a paid bug bounty program.

Trust links

Related policies and context

About AES Tech ->