We pride ourselves on telling the truth to our customers, and we're quite clear that if we receive an Australian warrant for access to information about one of our customers, then we respond. That's different from adding backdoors.
Our submission asks that the law be updated so we're allowed to talk about any surveillance capabilities that we may be asked to add, but not about which users are being surveilled. That way our customers know exactly what we are capable of.
Right now we haven't received any capability requests (TCN) which is the bit we're concerned about, because if they required us to add features to the product without telling all staff about them, that would make it hard to maintain and ensure security as things were refactored. And any staff who DID know about it would have to be extra careful about what they say anywhere, because they could inadvertently leak something about the capability.
We expect the law to be updated soon, and hopefully this will be addressed. Until then - honestly, nothing has changed. We still operate under exactly the same process - if we receive a warrant from Australian Federal Police we respond. If we receive any other type of request, we point them to the AFP and the mutual assistance treaties that are appropriate. But it's impossible for you to verify that, because if something HAD changed, we'd have lie - and that's frustrating to us.