Vulnerability Disclosure Policy
We test other people’s systems for a living, so we take reports about our own seriously. If you believe you have found a security issue affecting Nanorisk, we want to hear about it.
Scope
This policy covers systems operated by Nanorisk Limited:
- nanorisk.co.uk and www.nanorisk.co.uk — this website
- portal.nanorisk.co.uk — the Nanorisk Security Portal
Client systems assessed by Nanorisk are out of scope. If you have found an issue affecting one of our clients, please report it to that organisation directly — we cannot authorise testing of systems we do not own.
How to report
Email info@nanorisk.co.uk with the subject line “Security disclosure”. Please include:
- the affected host, URL, or endpoint
- a clear description of the issue and its likely impact
- the steps needed to reproduce it
- any supporting evidence — requests, responses, screenshots
Machine-readable contact details are published at /.well-known/security.txt.
What we ask of you
- Give us a reasonable period to investigate and remediate before disclosing publicly.
- Do not access, modify, or delete data belonging to anyone else. If you encounter personal data, stop and tell us.
- Do not run denial-of-service tests, send spam or phishing, or use social engineering against our staff.
- Test only against the systems listed above, and only to the extent needed to demonstrate the issue.
What you can expect from us
- We will acknowledge your report.
- We will keep you informed of our assessment and remediation progress.
- We will not pursue legal action against researchers who act in good faith and within this policy.
- We will credit you if you would like us to, once the issue is resolved.
Rewards
We do not currently operate a paid bug bounty. Reports are handled on the basis of good faith and professional courtesy, and we are glad to acknowledge researchers publicly where they wish.