Responsible Disclosure Policy
Effective 2026-06-21 · 2026-06-21
hey ema — Responsible Disclosure Policy
1. Purpose
By Loci Pty Ltd ACN 635 780 451 (Hey ema, we, us, our) welcomes reports from security researchers, Customers, and other members of the community about suspected vulnerabilities in Hey ema.
This Responsible Disclosure Policy explains how to report a security issue, what you can expect from us, and the rules we ask you to follow while testing.
This Policy should be read together with our Security Overview and Privacy Policy.
2. Scope
This Policy covers the production Hey ema service and our public websites operated by By Loci Pty Ltd. It does not cover third-party services, Customer-hosted content, or systems outside our control.
3. How to report
Please report suspected vulnerabilities to security@heyema.com. Include, where you can:
- a description of the issue and its potential impact;
- steps to reproduce the issue;
- the URL, feature, or component affected;
- any proof-of-concept code, screenshots, or logs; and
- your contact details so we can follow up.
If you need to send sensitive material, ask us for a secure channel.
For abuse of the service (for example spam, phishing, or AUP violations), use abuse@heyema.com instead.
4. What we will do
When we receive a good-faith report, we will:
- (a) acknowledge receipt within a reasonable time;
- (b) investigate the report and keep you informed of material progress where appropriate;
- (c) work to remediate confirmed vulnerabilities; and
- (d) notify affected parties where required by law or contract.
We do not currently offer monetary rewards (no bug bounty program).
5. Safe harbour for good-faith research
If you act in good faith and comply with this Policy, we will not pursue legal action against you solely for security research that:
- (a) is limited to identifying and reporting vulnerabilities to us;
- (b) does not access, modify, or delete data belonging to others (including other customers' data);
- (c) does not degrade the availability or integrity of Hey ema;
- (d) does not use social engineering, phishing, or physical attacks against our personnel, offices, or suppliers;
- (e) does not exploit a vulnerability beyond what is reasonably necessary to demonstrate it; and
- (f) gives us a reasonable opportunity to investigate and remediate before any public disclosure.
We cannot authorise activity that violates Applicable Law. You remain responsible for complying with laws that apply to you. This safe harbour is not a waiver of rights against anyone who acts in bad faith or outside these rules.
6. Coordinated disclosure
We ask that you:
- allow us a reasonable period to investigate and remediate before you disclose the issue publicly; and
- work with us on the timing and content of any public disclosure where practicable.
If you plan to publish details of a vulnerability, please contact us first at security@heyema.com.
7. Out of scope
The following are generally out of scope for this Policy (though we may still appreciate a heads-up):
- issues in third-party services not operated by Hey ema;
- social engineering or phishing against our staff or Customers;
- denial-of-service attacks or load testing without prior written approval;
- physical security issues at facilities we do not control;
- vulnerabilities in Customer-uploaded content or Customer-configured integrations; and
- findings that require unlikely user interaction or affect only obsolete browsers without security support.
8. Recognition
With your permission, we may acknowledge your contribution in release notes or a security-advisories page. We will not publish your name without your consent.
9. Contact
- Security reports: security@heyema.com
- Privacy matters: privacy@heyema.com
- General support: support@heyema.com
- Post: Security, By Loci Pty Ltd, 101 Camberwell Road, Hawthorn East VIC 3123, Australia