Capital · coordination · constructionCareers

Vulnerability disclosure

If you have found a vulnerability in software we operate or in a platform we license, report it to the address above. We acknowledge within two business days and will keep you informed until it is resolved.
Acknowledgement
Within two business days
Disclosure
Timeline agreed, not imposed
Bounty
None currently

What we commit to

  • We will not pursue legal action against a researcher acting in good faith under this policy.
  • We will agree a disclosure timeline with you rather than impose one.
  • We will credit you when the issue is resolved, unless you ask us not to.

Scope

In scope

  • Software licensed from the platform catalogue, in any deployment we operate.
  • This website and the enquiry handling behind it.
  • Client deployments are the client’s to disclose. If a report concerns one, tell us and we will route it without acting on the client’s behalf.

Out of scope

  • Findings that require a compromised device or a privileged internal account to reproduce.
  • Volumetric denial of service.
  • Reports produced solely by an automated scanner with no demonstrated impact.

On bounties

The practice does not currently run a paid bounty programme. Stated rather than implied.