Reporting a security problem

Recount handles other people’s accounting records and mailboxes. If you have found a way to reach data or functions you should not be able to reach, we want to hear about it, and we will not take action against you for telling us.

Email security@recount.au with enough detail to reproduce the problem: the URL or endpoint, the steps, and what you were able to see or do. Screenshots or a short recording help. Please do not open a public issue or post the detail publicly first.

What we do in return

Safe harbour

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your report as an authorised test rather than an attack. If a third party brings action against you for work that followed this policy, we will say publicly that it was authorised.

In scope

Anything else is out of scope, including the services we connect to on a customer’s behalf (Xero, Microsoft, Google) and the platforms we run on. Report problems in those to their own security teams; if the problem is in how we use them, that is in scope and we want it.

Rules we ask you to follow

Usually not accepted

Reports that describe only a missing or misconfigured header, an email policy record, a rate limit, TLS configuration, a version banner, or raw scanner output, with no demonstrated impact, will usually be closed without a fix. If you can show the impact, send it anyway.

If you have found customer data

Tell us immediately and do not download, copy, or keep it. We are an Australian business and a serious exposure may be notifiable under the Privacy Act, so the clock starts when we learn about it. Your report is what starts it.

This policy covers the Recount service. Machine-readable version: /.well-known/security.txt. Last updated 23 September 2026.

← Back to recount.au