Vulnerability Policy
How to report a security issue to us.
Last updated 31 July 2026.
Introduction
Arise Software Ltd is dedicated to developing and supporting systems that assist Māori organisations in the administration and process of grants and distributions to landowners and descendants. Ensuring the security of our systems is a top priority, and we value the role of security researchers in helping us maintain this security.
Scope
This policy applies to any digital assets owned, operated, or controlled by Arise Software Ltd, including our websites and other online services.
Reporting a vulnerability
If you believe you have discovered a vulnerability in any of our systems, we encourage you to report it to us as soon as possible. Please include as much information as possible, including:
- A description of the issue
- Steps to reproduce the vulnerability
- The page or screen it affects — a URL is ideal
- The system used (for example, operating system, browser)
- Any relevant screenshots or logs
Please do not send us passwords, access codes or anyone's login credentials, and please do not access, change or download data that is not your own. We will never ask you for a password.
Contact information
Please report vulnerabilities by email to support@arisesoftware.co.nz. Your report will be handled by David.
Acknowledgment and response
We aim to acknowledge receipt of your report as soon as possible, typically within 48 hours. We dedicate the necessary time to resolve each reported vulnerability and will keep you updated on our progress.
Vulnerability disclosure process
- Submission — send your report to support@arisesoftware.co.nz with the details listed above.
- Acknowledgment — we will acknowledge receipt of your report within 48 hours.
- Validation — we will validate and reproduce the issue.
- Resolution — we will work to resolve the vulnerability as quickly as possible, keeping you informed of our progress.
- Disclosure — we will notify you when the vulnerability has been resolved and discuss any necessary public disclosure.
Legal aspects and confidentiality
We will handle all reports in accordance with applicable laws. We are committed to protecting your privacy and will treat your report confidentially. We will not share your personal information without your consent, except as required by law. We request that you do not publicly disclose the vulnerability until we have had an opportunity to address it.
Safe harbour. If you follow this policy — report promptly, keep the detail confidential until we have fixed it, and do not access, change or delete data that is not your own — we will treat your research as authorised. We will not take legal action against you, or refer you to the authorities, for a good-faith report made under this policy.
Recognition
As a token of our appreciation, we offer personal recognition for significant vulnerability reports — a proper thank you from the person who fixed it, and credit by name if you would like it.
Review and update
This policy will be reviewed and updated by David as required.
Password requirements
Access to the systems we host is issued by us. Passwords must:
- Not contain the user's account name, or parts of the user's full name that exceed two consecutive characters
- Contain characters from three of the following four categories:
- English uppercase characters (A through Z)
- English lowercase characters (a through z)
- Base 10 digits (0 through 9)
- Non-alphabetic characters (for example
!,$,#,%)
Length and complexity requirements are enforced whenever a password is created or changed. Current settings are available to clients on request, in writing, for audit or governance purposes.