At Outwizar we take the security of our systems, and of the data we hold, seriously. If you have found a vulnerability in them, we want to hear about it.
Telling us
Tell us as soon as you can. The sooner we know, the shorter the window in which somebody else can use it.
- Email: security@outwizar.co.uk
- Encrypted: our OpenPGP public key — fingerprint
1B99 8912 ABF3 C7FC 528F 22EF 1FC6 5B87 25BC E7F7. Please use it if the report carries anything sensitive. - Machine-readable: outwizar.co.uk/.well-known/security.txt
This policy covers outwizar.co.uk and its subdomains, our iOS and Android apps, and our APIs. Anything operated by somebody else sits outside it, including the services we integrate with — we cannot give you permission to test what we do not run.
What to put in the report
- Where it happens: the page, endpoint or screen.
- What you think the flaw is.
- The steps that reproduce it, in the order you did them.
- Screenshots, a short recording or log lines, if you have them.
- Whether you would like to be credited, and under what name.
What we ask
- Stay within the law.
- Stop at proof. Establishing that a flaw is real is enough; going further turns a test into an incident.
- Test against your own account. Leave other people's accounts and data alone.
- Nothing noisy or coercive: no automated scanning, no phishing our staff or our users, nothing that takes the service down.
- Never make the report conditional on a payment. A finding held back until we pay for it is not a disclosure, and we will treat it as extortion.
- Give us time to ship a fix before you publish.
Data you come across
If testing puts somebody else's personal data in front of you, stop reading it and take no more of it than it took to show the flaw is real. Keep what you already have somewhere safe, do not pass it on or publish it, and delete it once we confirm the fix is live — at the latest one month after that. Tell us in the report what you were able to see, even roughly. Under UK GDPR that is what decides whether we owe the people affected a notification, and we cannot make that call without you.
What we will do
- Acknowledge your report within five working days. We would rather commit to a date we can hold than to a faster one we cannot.
- Come back within ten working days with our assessment: what we think it is, how serious, and what happens next.
- Rank the fix by how much harm it could do, how easily it could be used, and how many people it reaches.
- Credit you once the fix is live, if you want to be named.
- Agree a date with you if you would like to write the finding up publicly.
We do not pay for reports. There is no bug bounty here, and we would rather say so plainly than let you spend an evening finding out.
Things we will not treat as vulnerabilities
Some findings are real without being something we will act on here: missing security headers with no working exploit behind them, TLS or cipher-suite preferences on their own, raw scanner output with nothing demonstrated, cross-site scripting a user can only inflict on themselves, password-strength opinions, and anything in a service somebody else runs. Send them anyway if you believe we have judged one wrongly — just expect a slower reply.
Legal safe harbour
Work inside this policy and we treat your research as authorised. We will not report you, sue you, or ask anyone else to. If a third party pursues you over research you carried out within these rules, we will state on the record that you had our permission.
If you are not sure whether something is in bounds, email us before you test it. We would much rather answer a question than receive an apology.