Vulnerability Disclosure Program

Lendi Group takes cybersecurity seriously. We place emphasis on keeping our online service safe and strive to continuously improve. At the Lendi Group we understand you may choose to provide us feedback to help us improve.

Our Vulnerability Disclosure Program provides security researchers an appropriate process to formally disclose potential vulnerabilities, across our online platforms.

Acceptance Criteria 

The Vulnerability Disclosure Program specifically focuses on technical vulnerabilities. You can also refer to our privacy policy and security policy, which outlines the personal information handling practices and contains information on how to raise a privacy request or concern. 

We encourage security research, but cannot accept behavior that is destructive, actions that compromise our customers’ personal information or extends into social engineering attacks. Such actions are not considered security research and do not indemnify you from legal liability. 

We are also keen to learn of any potential vulnerability, so to help us understand your concerns, it is essential you provide us with sufficient information to allow us to reproduce your finding. Reports should be specific and based on fact. 

Submit Your Findings 

To submit your findings: 

  • Send an email to VulnerabilityDisclosure@lendi.com.au

  • Provide sufficient information so that our security team can reproduce your finding. You can help us by listing: 

  • Affected URLs. 

  • Name of account being used for testing. 

  • IP addresses used for testing. 

  • Step-by-step instructions, if the vulnerability is complicated to reproduce. 

  • Whilst submissions can be anonymous, it may help us confirm legitimacy if you provide your real name or link to an online biography. 

Hall of Fame 

Lendi Group’s policy does not provide financial compensation for the provision of your research findings. Security researchers may however derive value in having their name published online. If you find a meaningful vulnerability then we are happy to add your name here in future updates. 

Contributors

Website or Contact

Aya Atiya 

https://bugswagger.com

Nuno Abreu

@ Shadowstrike

Meowsint

https://www.linkedin.com/in/meowsint

Back to top

Follow us

Twitter
LinkedIn
Facebook
Youtube
Instagram

Download the Aussie App

We acknowledge the Traditional Owners of the many lands where we live and work and pay our respects to Elders past, present and emerging. We celebrate the stories, culture and traditions of Aboriginal and Torres Strait Islander Elders of all communities from the many lands where we live, work and gather.

© 2026 Lendi Group Distribution Pty Ltd ABN 27 105 265 861 Australian Credit Licence 246786. The Lendi Group Pty Ltd, which is the ultimate holding company of the Aussie and Lendi businesses is owned by numerous shareholders including; banks such as CBA, ANZ and Macquarie Bank, the Lendi founders and employees, and a number of Australian institutional investors and sophisticated investors including UniSuper.