Security
Security & responsible disclosure
Gettit runs a safe Australian marketplace that holds buyers’ payments until an order is complete. If you believe you have found a security vulnerability, we want to hear from you — and we will not take legal action against good-faith research.
How to report
Email a description of the issue, the steps to reproduce it, and its impact to:
The same address is published in our machine-readable security.txt. Please do not open a public issue or post details publicly before we have had a chance to respond.
What to expect
- We aim to acknowledge your report within 2 business days.
- We will keep you updated as we investigate and work on a fix.
- We will credit you once the issue is resolved, if you would like to be named. Please tell us how you would like to be credited.
Scope
In scope: the Gettit website (gettit.com.au), the Gettit API and the Gettit iOS and Android apps.
Please test only against your own accounts and data. The following are out of scope and not eligible for disclosure protection:
- Denial-of-service, volumetric, or load testing.
- Social engineering, phishing, or physical attacks against our staff or offices.
- Accessing, modifying, or deleting data that is not your own, or disrupting other members’ use of the service.
- Automated scanning that generates high request volumes against production.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your testing to be authorised, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue quickly. If a third party brings legal action against you for research conducted in line with this policy, we will make it known that your actions were authorised.