Responsible Disclosure Policy

Enero Group Limited, together with its subsidiaries (including BMF Advertising Pty Ltd (ABN 11 073 782 742), Hotwire Public Relations Group (DE 4693148), Orchard Marketing Pty Ltd (ABN 37 119 244 076), and ROI DNA, Inc (DE 5103234) (together, “Enero”, “we”, “our” or “us”) is committed to protecting the security of our systems, our people, and the data our clients trust us with.

We welcome reports from security researchers, customers, and members of the public who discover a genuine security vulnerability affecting something we build, own, or operate. This policy explains what to report, how to report it, what you can expect from us in return, and the protection we offer you for doing so in good faith.

We ask that you report a vulnerability to us using the process below, and give us a reasonable opportunity to investigate and fix it.

HOW TO REPORT

Email security@enero.com. This is the address published in our security.txt file at enero.com/.well-known/security.txt, and is the only channel we monitor for external vulnerability reports.

To help us act on your report quickly, please provide us with as much information as possible, such as:

Please write to us in English. If your report involves any sensitive information for example, personal data or client-confidential material, tell us that in your first message before sending it through to us.  We will arrange a secure way to review it.

IN-SCOPE

This policy covers systems that Enero itself owns and operates, including:

Out of scope

Please email us before you test if you are not sure whether something is in scope.

HOW TO TEST

What you can expect from us

Your reports are made voluntarily.  We do not offer financial or monetary reward for reports made under this policy.

We ask that you maintain confidentiality until we have remediated or mitigated the potential security vulnerability. Disclosure of any potential security vulnerability publicly or to a third party is not permitted without our express written consent.

Safe harbor

If you make a good-faith effort to comply with this policy including staying within the scope and testing guidelines set out above, we will not pursue or take legal action against you in connection with that research.  We will treat your access as authorised for that limited purpose.

If a third-party initiates legal action against you for activities that were consistent with this policy, we will take reasonable steps to make known that your actions were authorised under this policy.

This safe harbor does not extend to conduct outside this policy’s scope or guidelines, and does not apply where your activity involves accessing, retaining, or disclosing personal data or confidential information beyond what is reasonably necessary to demonstrate a vulnerability.

About this policy

This policy applies to Enero Group Limited and its subsidiaries and is published to meet Enero’s coordinated vulnerability disclosure commitments.

We may update this policy from time to time.  This policy was last updated on September 8, 2026.