Security & Vulnerability Disclosure
Last updated 25 March 2026
The security of our customers' data is fundamental to everything we do. We welcome responsible security research and are committed to working with the security community to make Manaia safer for everyone.
1. Reporting a Vulnerability
If you believe you have found a security vulnerability in any Manaia service, please report it to us responsibly. Do not disclose the vulnerability publicly until we have had a reasonable opportunity to address it.
Report to: security@manaia.io
For sensitive reports, you may encrypt your email using our PGP key (available upon request).
What to include in your report
- A description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- The affected service, URL, or component
- Any proof-of-concept code or screenshots (if applicable)
- Your preferred method of contact for follow-up
2. Scope
In scope
- app.manaia.io (consumer dashboard)
- auth.manaia.io (authentication gateway)
- dns.manaia.io (DNS resolver infrastructure)
- manaia.io (main website)
- API endpoints at *.manaia.io
- Manaia iOS and Android applications
- Manaia Home Lite firmware
Out of scope
- Third-party services (Stripe, AWS, Cognito) — report these to the respective vendor
- Social engineering or phishing attacks against Manaia staff
- Denial-of-service (DoS/DDoS) attacks
- Automated scanning that generates excessive traffic
- Issues in third-party dependencies with no demonstrable impact on Manaia
- Reports from automated tools without a demonstrated proof of concept
3. Safe Harbour
We consider security research conducted in accordance with this policy to be:
- Authorised — we will not pursue legal action against researchers who comply with this policy
- Lawful — we will not support prosecution of researchers acting in good faith
- Helpful — we view your effort as a contribution to the security of our users
To qualify for safe harbour, you must:
- Not access, modify, or delete data belonging to other users
- Not degrade the performance or availability of the service for other users
- Stop testing and report immediately if you encounter user data
- Not disclose the vulnerability publicly until we have confirmed it is resolved
- Use only your own test accounts for research
4. Our Commitment
When you report a vulnerability to us, we commit to:
- Acknowledge receipt — within 2 business days
- Provide an initial assessment — within 5 business days, including expected severity and timeline
- Keep you informed — provide updates as we work on a fix
- Credit you — with your permission, we will publicly acknowledge your contribution (if you wish to remain anonymous, we will respect that)
- Fix promptly — critical vulnerabilities will be prioritised for immediate remediation; others within 90 days
- Not retaliate — we will never take adverse action against a researcher who acts in good faith
5. Our Security Practices
For a summary of the security measures we employ to protect your data, see our Privacy Policy (Section 7: Security Measures). Key practices include:
- AES-256-GCM encryption at rest for all PII (via AWS KMS)
- TLS 1.3 encryption in transit for all connections
- DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) for resolver traffic
- Fail-closed role-based access controls (RBAC) with audit logging
- AWS GuardDuty, CloudTrail, and WAF for continuous monitoring
- Automated CI/CD security gates (syntax checks, TLS verification, secret scanning)
- Multi-AZ database redundancy in AWS Sydney region
- 30-day credential rotation with automated monitoring
Contact
Security reports: security@manaia.io
General support: support@manaia.io
Entity: Manaia Tech Pty Ltd (ABN 52 696 183 703)