Skip to content
Legal

Security.

How to report a vulnerability, what happens next, and when. If you have found something, we would rather hear it from you.

Last reviewed 2 September 2026.

How to report

Send it to security@staticsignal.co.uk. There is no form and no portal. Plain email is fine.

What we commit to

We acknowledge a report within two working days, tell you whether we can reproduce it within ten, and keep you informed until it is closed. If we decide not to act on something, we say so and give the reason rather than letting the thread go quiet.

We will credit you when a fix ships, if you want the credit. We do not run a paid bounty programme, and we would rather say that plainly than leave it ambiguous.

What we ask

  • 01Describe the issue clearly enough that we can reproduce it.
  • 02Include the steps, and evidence if you have it.
  • 03Stop at the point where the vulnerability is demonstrated. Do not go further into the system than that requires.
  • 04Do not access, change, or delete anyone else’s data. If you reach data that is not yours, stop and tell us what you saw.
  • 05Give us time to fix it before publishing.

Safe harbour

We will not pursue legal action against anyone who reports in good faith and follows the above. If you are unsure whether something you want to test crosses a line, ask us first — we will answer.

Client data

Data under processing is held for the engagement window and deleted within 30 days of acceptance. Access is single-operator, processing is EU-resident, and every custody event is recorded in an append-only log. The full terms are in the DPA summary.

A vulnerability that reaches data in custody is treated as an incident rather than a defect: affected clients are told, in writing, what we know and when we knew it.