Vulnerability Disclosure Policy

Last updated 10 September 2026 · Nanorisk Limited

We test other people’s systems for a living, so we take reports about our own seriously. If you believe you have found a security issue affecting Nanorisk, we want to hear about it.

Scope

This policy covers systems operated by Nanorisk Limited:

Client systems assessed by Nanorisk are out of scope. If you have found an issue affecting one of our clients, please report it to that organisation directly — we cannot authorise testing of systems we do not own.

How to report

Email info@nanorisk.co.uk with the subject line “Security disclosure”. Please include:

Machine-readable contact details are published at /.well-known/security.txt.

What we ask of you

What you can expect from us

Rewards

We do not currently operate a paid bug bounty. Reports are handled on the basis of good faith and professional courtesy, and we are glad to acknowledge researchers publicly where they wish.