Last reviewed: 19 August 2026
1. Reporting
Please email info@gskordeven.co.uk with the subject “Website Security Report”. Describe the affected address, the behaviour you observed, the date and time, and safe steps to reproduce it.
2. Safe research boundaries
Please do not access or alter other people’s data, disrupt availability, use destructive payloads, upload malware, attempt to establish persistence, perform denial-of-service testing, send bulk requests, or use social engineering.
3. Data handling
Stop immediately if you encounter personal or confidential information. Please do not copy, retain or publish it, and include only the minimum evidence needed.
4. No automatic reward or safe-harbour promise
This page does not create a bug-bounty programme, a contract, a payment promise or legal immunity. Good-faith reports made within these boundaries will be reviewed, but formal safe harbour can only ever be granted explicitly, in writing.
5. Response
A report will be acknowledged as soon as is reasonably possible. Remediation timing depends on severity, reproducibility, the level of hosting control available, and any third-party dependencies.
Reference framework
- Information Commissioner’s Office: UK GDPR guidance
- Information Commissioner’s Office: privacy notices and cookies
- Data Protection Act 2018
- Data (Use and Access) Act 2025
- Privacy and Electronic Communications Regulations 2003
- Electronic Commerce Regulations 2002