How we approach security
We aim to operate controls appropriate to the service, covering access permissions, credential handling, protection of data, software updates, monitoring, incident handling, availability and recovery.
No platform can promise absolute security, and we do not claim to. Security measures specific to a customer's processing belong in the agreed Data Processing Agreement.
What to include
- The URL or component affected, and a short description of the issue.
- The steps needed to reproduce it, using an account and data you are authorised to use.
- What you expected to happen, what actually happened, and when you observed it.
- A minimal proof of concept with secrets and unrelated personal data removed, plus a way to contact you.
Protecting people and data
Please do not access anyone else's account or records, copy more data than necessary, maintain access, disrupt availability, attempt social engineering, or test third-party providers without their own authorisation. If you come across personal information unexpectedly, stop, avoid looking further and tell us securely.
This page is not permission to carry out penetration testing, and it does not grant immunity from third-party or statutory claims. Any testing beyond what is described here needs to be agreed with us in writing first. Good faith reports are handled proportionately.
How reports are handled
Reports are assessed according to risk, and we coordinate communication so that users are not exposed before an issue is mitigated.
Where a report involves personal data, the relevant breach notification processes also apply. Reporting something to us does not replace any obligation you have to notify a controller, regulator or affected individual. We do not operate a paid bounty programme.
Sign Up