Security
Effective date: 15 July 2026
Provider: GigPigs Pty Ltd, trading as iD Comedy, Stand Up Sydney and GigPigs, and operator of The Comedy (thecomedy.com.au) and Live Stand Up Comedy (livestandupcomedy.com).
We take the security of the GigPigs / Stand Up Sydney / iD Comedy / The Comedy / Live Stand Up Comedy Services seriously. If you're a security researcher and you've found a vulnerability, we want to hear from you — this page explains how to report it safely.
How to report
Email security@gigpigs.app with:
- a description of the issue and where you found it (URL/endpoint/app screen);
- steps to reproduce, and proof-of-concept if you have one;
- the potential impact as you see it.
We'll acknowledge your report, keep you updated, and let you know when it's fixed. within 5 business days.
Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we'll treat your report confidentially. To qualify, please:
- avoid harm — don't access, modify or delete data that isn't yours, and don't degrade the Services;
- use only your own test accounts/data, or data you're authorised to access;
- stop and report immediately if you encounter personal data, and don't store, share or exfiltrate it;
- give us reasonable time to fix the issue before disclosing it publicly, and coordinate any disclosure with us.
Out of scope
The following generally don't qualify (unless you can show real, exploitable impact):
- reports from automated scanners without a working proof-of-concept;
- missing security headers, cookie flags, or best-practice suggestions with no demonstrated impact;
- social engineering, phishing, or physical attacks against our staff or offices;
- denial-of-service (DoS/DDoS) or spam/volumetric testing;
- issues in third-party services we use (report those to the third party — e.g. the ticketing, payment, or hosting provider).
What we ask you not to do
- Don't publicly disclose before we've fixed it and agreed timing.
- Don't demand payment in exchange for a report. We don't currently run a paid bug bounty, but we're grateful and will credit you if you'd like.
Recognition
With your permission, we're happy to acknowledge researchers who help us keep the platform safe..