Vulnerability Disclosure Policy

Last updated: 10 August 2026

Our commitment

Secvura Limited takes the security of its systems, and of the data entrusted to it, seriously. If you believe you have found a security vulnerability in a system that we own or operate, we want to hear about it. This policy explains how to report a vulnerability to us, what is in scope, the rules of engagement, and what you can expect from us in return. It applies to security researchers and to anyone else who identifies a vulnerability in our systems, whether deliberately or in the course of ordinary use.

How to report

Please send your report to security@secvura.com. To help us triage and resolve the issue quickly, please include, where you can:

  • the domain, page, URL, endpoint, or component affected;
  • a clear description of the vulnerability and the impact you believe it could have;
  • the steps needed to reproduce it, together with a minimal, non-destructive, and proportionate proof of concept; and
  • a way for us to contact you if we have follow-up questions.

Please report what you have found as soon as reasonably practicable after discovering it, and please keep the details confidential while we investigate and address the issue, unless we agree a different disclosure arrangement with you or disclosure is required by law. If you would like to send information to us securely, email us first and we will arrange a secure channel.

What is in scope

This policy applies to the Secvura website at secvura.com, its subdomains, and other applications, endpoints, and services that Secvura Limited owns or operates.

Where a Secvura service is hosted or provided using third-party infrastructure, this policy authorises testing only of the Secvura-controlled applications, configurations, endpoints, and data. It does not authorise testing of the underlying infrastructure, platform, or services belonging to a third party.

The following are out of scope:

  • Client systems and data. This policy does not authorise you to test, scan, access, or otherwise interact with any client environment, application, network, account, or data belonging to a client or other third party, even where Secvura manages, audits, assesses, hosts, administers, or otherwise has access to it. If you believe you have found a vulnerability in a system belonging to one of our clients, stop immediately and notify us, so that we can inform the client through authorised channels. We have no authority to permit testing of a client's systems.
  • Third-party services. Any infrastructure, hosting, email, analytics, software, platform, or other third-party service that we rely on but do not own or control. If you identify a vulnerability in a third-party product or service that affects Secvura, please report it to us rather than testing the third party beyond what is reasonably necessary to demonstrate the impact on Secvura, and we may coordinate disclosure with the relevant provider.
  • Disruptive or physical methods. Anything requiring physical access to our premises or equipment, the social engineering or phishing of our people, denial-of-service or distributed denial-of-service testing, or any activity likely to interrupt, degrade, overload, or impair our services.

To keep us focused on issues that matter, the following will generally be treated as informational and may be closed without further action unless accompanied by a working, impactful proof of concept:

  • missing HTTP security headers, such as CSP, HSTS, or X-Frame-Options, with no demonstrated exploit;
  • unauthenticated output from automated scanners, such as Burp, Nessus, or ZAP logs;
  • descriptive error messages or stack traces that do not expose sensitive data; and
  • issues affecting only obsolete, unsupported, or end-of-life software or browsers.

We may also close reports where the reported behaviour is expected functionality, does not present a material security impact, is already known to us, or is otherwise not reasonably actionable.

Rules of engagement

When investigating or reporting a vulnerability under this policy, you must:

  • act in good faith, and take care to avoid disruption, privacy violations, and any degradation of our services;
  • only interact with accounts, systems, services, and data that are within the scope of this policy, or that you own or have explicit permission to use;
  • observe data minimisation: interact with the smallest amount of data necessary to demonstrate the vulnerability, and do not view, copy, modify, retain, or exfiltrate any sensitive or personal data beyond what is strictly necessary;
  • stop testing immediately, and notify us, if you encounter sensitive personal data, credentials, authentication tokens, private keys, confidential client information, or evidence that a system or data belongs to a third party;
  • not establish persistence, create accounts, change permissions or configurations, install software, deploy code, or otherwise modify systems or data, except where the minimum modification is strictly necessary to demonstrate the vulnerability and has been expressly agreed with us in advance;
  • securely delete any local copies of Secvura data obtained during your research as soon as they are no longer required to report or verify the vulnerability, subject to any legal obligation that requires you to retain them;
  • not use any technique that interrupts, degrades, overloads, or denies our services, and not carry out any social-engineering, phishing, or physical attack against our people; and
  • comply with all applicable laws at all times.

If you are unsure whether a proposed testing activity falls within this policy, please contact us before carrying it out.

What you can expect from us

If you report a vulnerability in good faith and in line with this policy, we will:

  • aim to acknowledge your report within three working days;
  • aim to provide an initial assessment of the report, including whether we consider it to be in scope and whether we need further information, within ten working days;
  • prioritise remediation according to the risk and impact of the issue;
  • keep you reasonably informed as we work to resolve it; and
  • where appropriate, and with your consent, credit your contribution once the issue has been resolved. We will not publish your identity without your permission.

These are response targets rather than guaranteed deadlines. We may ask you for more information or, where appropriate, ask you to retest a fix. Where several reports concern the same underlying issue, we may treat them as a single vulnerability report and, where appropriate, credit the first report that gave us enough information to identify it.

This is not a bug-bounty programme. We do not offer or promise financial rewards or other compensation for vulnerability reports.

Disclosure and confidentiality

Please do not publicly disclose a vulnerability, or its details, while we are investigating or remediating it, unless we have agreed a disclosure timeline with you. Where public disclosure is appropriate, we will work with you in good faith to agree a reasonable timeline.

This does not prevent disclosure where it is required by law, a court order, or a competent regulator, or where disclosure to a relevant third party is reasonably necessary to investigate or remediate the vulnerability. Where we are legally permitted to do so and it is reasonably practicable, we will let you know before making such a disclosure.

Authorisation and legal safe harbour

The Computer Misuse Act 1990 makes certain unauthorised access to computer material an offence. To give security researchers clarity, Secvura Limited authorises security research and vulnerability disclosure activities that are carried out in good faith and strictly in accordance with this policy, solely in respect of systems and services that Secvura Limited owns or controls and that fall within the scope of this policy.

Where you have acted in good faith and complied fully with this policy:

  • we will not bring or pursue a civil claim against you in connection with security research and disclosure activities that are authorised by this policy;
  • we will not seek to initiate or support a criminal prosecution against you in connection with security research and disclosure activities that are authorised by this policy; and
  • if a third party brings a claim against you arising from activities that were authorised by this policy, we will take reasonable steps to make known to the relevant court or authority that your actions were authorised by Secvura Limited.

These commitments do not prevent us from complying with a legal obligation, court order, or regulatory requirement, and they do not prevent us from responding appropriately to activity that falls outside this policy.

This authorisation applies only to systems and services that Secvura Limited owns or controls. It does not extend to, and we have no authority to grant permission in respect of, any third-party infrastructure, service, system, account, or client environment. This policy does not waive, limit, or affect any rights belonging to a third party.

Nothing in this policy requires or permits you to break the law, and nothing in it limits any right or remedy Secvura Limited may have in respect of activity carried out in bad faith, or otherwise outside the terms of this policy. For the purposes of security research that falls within this policy, this policy is Secvura Limited's prior written authorisation to carry out the activities it expressly permits.

How we handle your personal data

Any personal data you include in a report, such as your name or contact details, will be processed to assess, investigate, remediate, and respond to the report, to communicate with you about it, to keep appropriate security and audit records, and to comply with our legal obligations. Our Privacy Policy explains how we handle personal data more generally.

Changes to this policy

We may update this policy from time to time. The date at the top of the page shows when it was last changed, and the version that applies is the one published here at the time you report an issue.

Contact

Vulnerability reports and questions about this policy can be sent to security@secvura.com.