Skip to content
Legal
Security Contact & Disclosure
How to report a suspected security issue and what happens next.
Reporting
Suspected vulnerabilities can be reported through the contact form, marked for the attention of the security team. Please avoid including exploit detail in unencrypted correspondence.
What to include
A description of the issue, the affected URL or component, the steps required to reproduce it, and any observed impact.
What to expect
Reports are acknowledged, triaged against severity and tracked to resolution. We will confirm when a fix has been deployed.
Please do not
Access, modify or exfiltrate data belonging to other organisations, degrade service availability, or conduct social engineering against staff or customers.
