Contact
Email [email protected] with the subject “Website security”. Use email if the enquiry form itself is affected.
The published security contact is also identified at security.txt. This reporting route does not provide permission to test a system.
Website controls
The website uses encrypted connections through Cloudflare and is hosted on Microsoft Azure. Cloudflare terminates the browser’s encrypted connection.
The contact form uses validation, rate limiting and Cloudflare Turnstile. Website response policies restrict script and frame sources and prevent other sites from framing the pages.
These measures describe the website configuration. They do not establish security certification, an independent audit or freedom from vulnerabilities. Email correspondence is not an end-to-end encrypted reporting system.
Authorisation boundary
Ordinary observation of publicly accessible pages may be reported. Obtain express written authorisation before intrusive testing or access beyond ordinary website use.
Do not conduct denial-of-service tests, credential attacks, destructive exploitation, social engineering, malware deployment or testing of third-party services without their permission.
Do not access, alter, copy or disclose another person’s information to demonstrate a concern. If information is exposed unexpectedly, stop and report the minimum facts needed to locate the issue.
Report contents
Provide the affected URL or component, the time observed, a concise description and non-sensitive steps sufficient to explain the behaviour.
Do not send live credentials, secret keys, personal records or a working exploit containing harmful payloads. Ask for an appropriate exchange method if additional sensitive evidence is necessary.
Handling and disclosure
Where lawful and necessary, the relevant details may be provided to a competent authority or to the provider responsible for hosting or website security.
This notice does not promise a response deadline, reward, bug bounty, legal immunity or permission to continue testing. Any legally required incident notification remains governed by applicable law.
Public disclosure should avoid exposing personal information, credentials or details that facilitate continuing harm.
Records and changes
Security-related information is subject to the Privacy notice and any applicable preservation requirement.
Questions or complaints may be sent to the same email address or to the registered office in the Legal notice. This notice may change from its stated effective date.
