Report a security concern privately.
Help us investigate without exposing the people and systems affected.
Make a bounded report.
Email support@yumait.com.au with a brief description, affected public component or supported release, expected versus observed behaviour, and a minimal reproduction that contains no live secrets or customer data.
If sensitive evidence is needed, ask for an appropriate private transfer channel first. Do not post it in a public GitHub issue. Testing must stay within systems and accounts you are authorized to assess; this page is not authorization to attack customer environments.
What happens next.
The team can clarify scope, request further evidence, and coordinate next steps with the reporter. A report should distinguish a reachable weakness from a hypothesis and explain any prerequisites or compensating controls.
This is a private reporting channel, not a bug-bounty promise, a safe-harbour agreement, or a guaranteed response-time commitment. For urgent concerns, mark the subject clearly and avoid sending unnecessary sensitive detail.