← maturin.co.uk // Responsible disclosure

Report a vulnerability

We take the security of our own systems as seriously as our clients'. If you believe you've found a vulnerability in anything we operate, we want to hear about it, and we'll treat you as a partner, not a threat.

Scope

This policy covers systems operated by Maturin Security Ltd, including this website (maturin.co.uk) and its subdomains. Client systems and third-party services we use are out of scope. Please report issues in those directly to their owners.

How to report

Email security@maturin.co.uk with enough detail for us to reproduce the issue: affected URL or system, steps to reproduce, and impact as you understand it. Please don't include sensitive personal data in your report.

What you can expect from us

Safe harbour

We will not pursue legal action against, or report to law enforcement, anyone who researches and reports vulnerabilities in good faith and within this policy: make a genuine effort to avoid privacy violations, data destruction, and service disruption; don't access or modify data that isn't yours; give us reasonable time to remediate before public disclosure; and don't exploit a finding beyond what's needed to demonstrate it.