Security
Responsible Disclosure Policy
Security researchers help make the internet safer. If you discover a vulnerability affecting VaultLayer, we encourage you to report it responsibly. We will investigate every genuine report.
Reporting a Vulnerability
Please email security@vaultlayer.co.uk.
Include:
- Description of the issue
- Steps to reproduce
- Affected URL
- Screenshots (if helpful)
- Proof of concept (where appropriate)
- Your contact details
What We Ask
Please:
- Give us reasonable time to investigate.
- Avoid accessing customer data.
- Avoid disrupting our services.
- Do not publicly disclose vulnerabilities until we've had an opportunity to fix them.
- Act in good faith.
What You Should Not Do
Please do not:
- Perform denial-of-service attacks.
- Modify or delete customer data.
- Access accounts you do not own.
- Attempt social engineering against our staff or customers.
- Install malware or persistence mechanisms.
- Use automated scanners aggressively against production services.
Our Commitment
When you report a legitimate vulnerability, we will:
- Acknowledge your report.
- Investigate promptly.
- Keep you informed of progress.
- Notify you when the issue has been resolved.
- Credit you publicly (if you would like recognition).
Response Targets
| Stage | Target |
|---|---|
| Acknowledgement | Within 1 business day |
| Initial assessment | Within 3 business days |
| Status updates | At least every 7 days |
| Resolution | As quickly as possible based on severity |
Safe Harbour
If you act in good faith and follow this policy, we will not pursue legal action against your security research. We consider authorised security testing performed under this policy to be conducted with our permission.
This does not extend to activities that:
- intentionally damage systems
- access customer information
- disrupt services
- violate applicable laws
Hall of Fame
We appreciate the work of the security community. Researchers who responsibly disclose valid vulnerabilities may, with permission, be recognised on this page.
No disclosures have been published yet.
Security Contact
Back to Security · Trust Centre