Last updated 5 October 2026
Reporting a Security Issue
1. We want to hear from you
If you think you have found a security weakness in anything Process Link Pty Ltd runs, please tell us. We will work with you to understand it and fix it, and we will not treat a good-faith report as an attack.
2. How to report
Email security@processlink.com.au with:
- what you found, and where (the web address, app or device)
- the steps to reproduce it
- what you think someone could do with it
- how we can contact you, if you want us to
Send only as much data as it takes to show the issue. Please do not send other people’s personal information or passwords. You can report anonymously.
3. What we will do
- Confirm we have your report within two business days.
- Tell you what we think of it and what we plan to do, and keep you informed while we fix it.
- Tell you when it is fixed.
- Thank you publicly once it is fixed, if you would like us to.
4. What this covers
- this website
- Portal and the apps at processlink.com.au addresses, such as Shift Link, Process Mail, Files, Help Desk, Dossier and Connect
- Scribe, including our gateway software and our Node-RED nodes
It does not cover:
- services run by our suppliers, such as our hosting, database and email providers. Please report those to the supplier
- phishing or other social engineering of our staff or customers
- physical access to our offices or to customers’ sites
- denial of service, or anything that floods a service
- automated scanner output that does not show a real way to cause harm
5. How to test
- Test only with accounts you own, or that we have given you for testing.
- Do not view, change or delete other people’s data. If you reach some by accident, stop, do not keep a copy, and tell us.
- Never test against a customer’s plant, PLC or gateway. Industrial equipment can stop production or affect safety. If a finding needs equipment to prove, tell us and we will test it with you on our own.
- Do not disrupt a service or degrade it for other users.
- Give us 90 days, or until the issue is fixed if that is sooner, before you publish anything about it.
6. Our commitment to you
If you follow this page in good faith, we will treat your research as authorised, and we will not take legal action against you or ask anyone else to. If someone else takes action against you for research done under this page, we will make it known that you had our authorisation.
7. Rewards
We do not run a paid bug bounty. We are grateful for every report, and we will credit you if you would like us to.
How we handle personal information, including anything in a report, is in our Privacy Policy.