Collaborative Aotearoa Security Policy

Overview

Our security policy outlines how we protect our platform, data, and users. We are committed to maintaining a high standard of security and protecting the privacy of our community members.

Responsible Disclosure

We encourage security researchers to report vulnerabilities responsibly. If you discover a security issue, please:

  • • Email our security contact at support@redux.nz — this is the fastest route and is monitored for security reports
  • • Or contact us via our contact page
  • • Reference our security.txt file for machine-readable reporting details

🔍 Scope

This policy covers the Collaborative Aotearoa website and member platform at collab.org.nz, including our member portal, event registration, and resource library.

Out of scope: third-party services we rely on but do not operate (report those to the provider), findings that require physical access to a member's device, social engineering of our staff or members, and volumetric denial-of-service testing.

🤝 Safe Harbour

If you make a good-faith effort to comply with this policy during your research, we will treat your work as authorised, will not pursue legal action against you, and will work with you to understand and resolve the issue quickly. If a third party brings action against you for research conducted within this policy, we will make that authorisation clear.

👩‍💻 Our Expectations

When conducting security research on our platform, we ask that you:

  • • Do not perform actions detrimental to users or infrastructure
  • • Avoid testing that could degrade our services
  • • Do not access or modify data that doesn't belong to you
  • • Report findings privately before public disclosure
  • • Respect user privacy and data confidentiality

📊 Response Timeline

  • Acknowledgment: Within 24 hours
  • Initial assessment: Within 72 hours
  • Status updates: Weekly until resolved
  • Resolution: As quickly as possible based on severity

🇳🇿 Our Obligations in Aotearoa New Zealand

We work with primary care practices, PHOs, and the wider health sector, so we hold ourselves to the standards that sector expects:

  • Privacy Act 2020 — we handle personal information in line with the information privacy principles, including how it is collected, stored, used, and disclosed.
  • Health Information Privacy Code 2020 — where the information we hold is health information, we apply the Code's rules in addition to the Act.
  • HISO 10029:2022 Health Information Security Framework — we use the sector's security framework as our reference point for protecting health-sector information.

🔔 If a Breach Occurs

Under the Privacy Act 2020, where a privacy breach has caused or is likely to cause serious harm, we must notify the Office of the Privacy Commissioner as soon as practicable after we become aware of it, and notify the people affected.

Our commitment: we will begin assessing any suspected breach immediately on becoming aware of it, notify the Privacy Commissioner and affected individuals as soon as practicable where the threshold is met, and tell affected members what happened, what information was involved, and what we are doing about it. Where a member practice or PHO is also affected, we will contact them directly so they can meet their own obligations.

🚀 Continuous Improvement

We are always working to improve our security posture. We review and update our security practices, carry out security reviews of the platform, and keep our dependencies patched to protect our community.

Last Updated: 29 July 2026

Next Review: 29 July 2027

We review this policy at least annually, and after any material change to the platform or to our obligations. Our security contact details are also published at /.well-known/security.txt.

Security Policy | Collaborative Aotearoa