- Effective
- 2 August 2026
- Version
- 2.0.0
- Scope
- Researchers and users reporting suspected security vulnerabilities
On this page
Vulnerability Disclosure Policy
We welcome responsible reports that help protect our customers and platforms. This policy does not authorise unrestricted security testing.
1. Reporting
Submit a report through the support portal with the affected hostname or product, clear reproduction steps, impact, evidence and contact details. Do not include unnecessary personal data or secrets.
2. Good-faith expectations
- Test only accounts and data you own or are authorised to use.
- Stop if you access personal data, credentials, payment data or another customer’s environment.
- Do not download, alter, delete, retain or disclose data.
- Do not use automated high-volume scanning, denial of service, social engineering, physical intrusion or malware.
- Do not test suppliers, venue networks or customer systems without separate permission.
- Allow reasonable time for investigation before public disclosure.
3. Out of scope
Clickjacking without meaningful impact, missing cosmetic headers, self-XSS, rate-limit observations without exploit, spam, version disclosure, denial-of-service testing and issues requiring an already-compromised administrator account are generally out of scope.
4. Our response
We will acknowledge credible reports, assess severity and communicate material progress where practical. We do not operate a public bug bounty and do not promise payment, credit or a particular remediation date.
5. Safe harbour
Where a researcher acts in good faith, remains within this policy and avoids harm, we will not seek legal action solely for the authorised research. This does not protect unlawful conduct, extortion, privacy breach, service disruption or testing outside our authority.
Legal notices
Formal notices must be sent using the notice method stated in the applicable Order or through the authenticated customer portal. Where no method is stated, notices may be delivered to the registered office above. Operational support messages are not formal legal notices unless expressly identified as such.
Contracting entity: DM Digital UK Services Ltd, company number 17166861, registered office Hoults Yard, Mailing Exchange, Walker Road, Newcastle upon Tyne, NE5 2HL, United Kingdom.
