Sign up

Vulnerability disclosure policy

About this policy

Last updated 16 April 2025, 8:47am

Air New Zealand places the highest priority on the security and privacy of our information systems to safeguard our customers' and employees' data.

The vulnerability disclosure policy has been established to provide security researchers with clear guidelines for responsibly conducting vulnerability discovery activities on Air New Zealand's systems and websites. It also outlines the procedures for submitting identified vulnerabilities to Air New Zealand.

This page specifies the systems and types of research covered under this programme, the process for submitting vulnerability reports, and the requirements for the disclosure of submitted vulnerabilities.

If you identify a security vulnerability within our information systems, please refer to the information provided below for guidance on submitting a disclosure.

Scope

The following websites and their subdomains are in scope for the vulnerability disclosure policy programme.

If you discover a domain that is not included in the above list but you believe it may be owned by Air New Zealand, please contact our information security team. We will inform you if the domain is in scope of the vulnerability disclosure policy programme.

Guidelines for security research

These guidelines are designed to help both you and Air New Zealand when you find a security issue with our systems. If you're doing security testing, please:

  • Make every effort to avoid actions that:
    • Breach the privacy of individuals.
    • Affect the performance of a system for our customers.
    • Disrupt or damage any "live" systems.
    • Destroy or corrupt Air New Zealand data.
  • Perform research only within the scope as set out above.
  • Delete and don't share any confidential information or personal information you might have obtained.
  • Keep any security issues you discover within our systems confidential between yourself and Air New Zealand until we have the opportunity to fix them.
  • Don't commit any illegal activity.
  • Don't breach any relevant laws in the country of your origin and from where the security testing is taking place.

Reporting a vulnerability

Please report your findings to our information security team. By emailing or providing a disclosure to us, you agree that we can use your submission and its contents to ensure the security, integrity, and reliable operation of our technology and business.

If you're uncomfortable sending any of the following content by email, you may mask or redact sensitive content. If you want to encrypt data using the PGP key, contact our information security team and ask for one.

What to include in your disclosure

  • Clear description and evidence of the vulnerability, such as logs, screenshots, or web responses.
  • Detailed steps to reproduce the issue.
  • Any platforms, operating systems, or versions that are relevant.
  • Any relevant IP addresses or URLs.
  • Any supporting evidence you've collected, such as logging or tracing.
  • Your assessment of the exploitability or impact of the issue.
  • Your name, role (if appropriate) and contact details.

You can view our security.txt file.

What to expect after reporting a vulnerability

Upon receiving a vulnerability disclosure, we will take the following steps:

  1. Acknowledgement: We will confirm receipt of your disclosure and provide you with a tracking number for reference. Our goal is to acknowledge all disclosures within three business days, excluding public holidays.
  2. Clarification and communication: We will engage with you to address any queries we have regarding your disclosure.
  3. If you act in good faith and follow this policy, then we make the following commitments to you:
    • The information that you share with us as part of this process will be kept confidential within Air New Zealand and our directly contracted suppliers; and
    • Your contact details won't be shared with third parties, without your permission; and
    • We will not initiate legal action against people attempting to find vulnerabilities within our systems who adhere to this policy.