At Swift Centre, the security of our systems and data is a priority. We value the security research community and recognise the part researchers play in finding problems before anyone else does. If you believe you have found a vulnerability in our systems, we'd like to hear about it.
This policy is published by Swift Centre Research Ltd (company number 14003610) and covers swiftcentre.org and our related applications.
Reporting a vulnerability
Send your finding to info@swiftcentre.org with as much detail as you can:
- what the vulnerability is
- how to reproduce it
- what someone could do with it
- any proof-of-concept code or screenshots, if you have them
Please give us reasonable time to fix the issue before making it public.
What we commit to
- We will not take legal action against you provided you follow this policy.
- We will acknowledge your report and keep you informed as we work on it.
- We will credit you publicly for the find, if you'd like us to.
Rules of engagement
- Don't do anything that could damage or interrupt our systems, data or services.
- Don't access, modify or delete data that isn't yours. If you come across personal information, stop and tell us rather than exploring further.
- Don't run automated scanning that generates significant load.
- Don't use social engineering, phishing or physical attacks against our staff or offices.
Recognition
If you responsibly disclose a valid security issue, we may offer a reward as a token of thanks. We decide this case by case, based on how serious the issue is and the quality of the report. There is no fixed scheme and no guarantee of payment.
Out of scope
Reports that describe theoretical problems with no demonstrated impact, findings from automated scanners without analysis, and issues in third-party services we don't control are generally out of scope — though if you're not sure, send it anyway and we'll take a look.