Skip to main content

Questacon is a division of the Department of Industry, Science and Resources (DISR) and follows departmental policies and processes. The Department maintains a Vulnerability Disclosure Policy that outlines how security researchers and members of the public can report potential security vulnerabilities affecting departmental systems, products and services, including those operated by Questacon.

If you believe you have identified a security vulnerability affecting a Questacon website, application or digital service, please refer to the Department's Vulnerability Disclosure Policy. The policy outlines how to report potential security vulnerabilities, the information to include in a report, responsible disclosure requirements, and how reports are managed.

Questacon supports responsible disclosure and encourages security researchers and members of the public to report potential vulnerabilities through the Department's established process. Please do not publicly disclose a vulnerability until the Department has had an opportunity to investigate and address the issue.

For full details, including reporting instructions and contact information, see the Department of Industry, Science and Resources' Vulnerability Disclosure Policy.