Last updated: July 17, 2025.
This policy is to help you and us, if you find a security issue in our systems.
Usable Balance Limited (UB) takes the security, confidentiality, integrity and privacy of our information seriously. We are always looking to increase and improve our security. If you think there is a security issue in our systems, please tell us so we can fix it.
We value your feedback. Letting us know if you think there is a security issue with our systems helps us to maintain the security and privacy of our information.
We will work with you to validate and promptly fix the issue. Where we get a report about systems run by our third-party suppliers we may need to work with you to report the vulnerability to them.
Please only act within the scope outlined in this policy.
We do not pay 'bug bounties' or pay for reported security issues.
Make sure you follow the policy guidelines. If you find a security issue in our systems, please do not:
If you follow this Responsible Disclosure Policy (including 'Acting responsibly') and report a security issue to UB, we commit to:
Scope includes but is not limited to:
If you do not know if a service is within scope, please email us at ResponsibleDisclosure@usablebalance.com
The following test types and findings are excluded from the scope:
If you believe you've found a security issue in one of systems, please let us know by emailing: ResponsibleDisclosure@usablebalance.com
Include the following details:
NZITF operate a coordinated vulnerability disclosure process where the finder of a security issue can use NZITF to notify affected vendors.