Report a vulnerability
We take the security of our own systems as seriously as our clients'. If you believe you've found a vulnerability in anything we operate, we want to hear about it, and we'll treat you as a partner, not a threat.
Scope
This policy covers systems operated by Maturin Security Ltd, including
this website (maturin.co.uk) and its subdomains. Client
systems and third-party services we use are out of scope. Please
report issues in those directly to their owners.
How to report
Email security@maturin.co.uk with enough detail for us to reproduce the issue: affected URL or system, steps to reproduce, and impact as you understand it. Please don't include sensitive personal data in your report.
What you can expect from us
- Acknowledgement of your report within 2 business days.
- An assessment and expected timeline within 10 business days.
- Updates as we remediate, and a heads-up when the fix ships.
- Credit for the find, if you'd like it, once resolved.
Safe harbour
We will not pursue legal action against, or report to law enforcement, anyone who researches and reports vulnerabilities in good faith and within this policy: make a genuine effort to avoid privacy violations, data destruction, and service disruption; don't access or modify data that isn't yours; give us reasonable time to remediate before public disclosure; and don't exploit a finding beyond what's needed to demonstrate it.