Skip to content
Security

Responsible Disclosure Policy

How to report a suspected security issue affecting this website or our public-facing systems.

We welcome good-faith reports of suspected security issues affecting this website or our public-facing systems. Reports from the security community help us find and fix problems faster.

This policy describes what we ask of reporters and what reporters can expect from us. It does not authorize testing against client environments.

Scope

Client environments are explicitly out of scope. Testing systems belonging to our clients requires that client's own written authorization.

  • This public website and its publicly reachable endpoints
  • Publicly exposed systems that we operate directly

How to report

Requests and questions can be submitted through the contact page on this website. Please include enough detail to reproduce the issue: the affected URL or component, a description of the behaviour, the steps taken, and any supporting output. A suggested severity assessment is helpful but not required.

Good-faith guidelines

  • Avoid actions that could degrade availability, such as denial-of-service or high-volume automated scanning
  • Do not access, modify, or exfiltrate data belonging to other people or organizations
  • Stop testing as soon as a vulnerability is identified and report it
  • Do not use social engineering, phishing, or physical intrusion techniques
  • Give us reasonable time to remediate before any public disclosure
  • Keep report details confidential until remediation is confirmed

What we commit to

  • Acknowledge receipt of a report within a reasonable period
  • Assess and triage the report and keep the reporter informed of progress
  • Work to remediate confirmed issues on a risk-appropriate timeline
  • Not pursue action against reporters who follow this policy in good faith
  • Credit reporters where they wish to be acknowledged

Rewards

There is no monetary bug bounty programme at this time. Valid reports are genuinely appreciated and will be acknowledged on request.

Please note

This document is published for transparency and describes current practice. It is general information, not legal advice, and it does not replace the written agreement covering a specific engagement.