Vulnerability Disclosure Policy

If you think you've found a security problem on this website, we want to hear about it, and we'll treat you fairly for telling us.

Last updated: September 2026

Reporting a vulnerability

How to report

Email hello@yellanddigital.co.uk with "Security" in the subject line. Our machine-readable contact details are also published in our security.txt file.

Please include:

  • A description of the issue and where you found it (the page or URL)
  • The steps needed to reproduce it
  • What you think the impact could be
  • Any screenshots or proof-of-concept details that help us confirm it

Please don't include sensitive personal data in your report. If you need to share something private, tell us and we'll arrange a secure way to do it.

What's in scope

  • The yellanddigital.co.uk website and its pages
  • The contact form and the way it handles submitted data

What's out of scope

  • Websites we've built or manage for clients. If you find something on a client site, please tell the site owner, or tell us and we'll pass it on
  • Third-party services we use, such as Cloudflare, Microsoft Clarity and email providers. Please report those to the vendor directly
  • Denial-of-service or load testing
  • Social engineering, phishing, or physical attacks against us or anyone connected to us
  • Spam, or automated scanner output submitted without checking that the issue is real
  • Reports of missing best-practice headers or settings with no demonstrated impact

Please act in good faith

  • Only test against your own data and accounts, and don't access, change or delete other people's data
  • Stop as soon as you've shown the issue exists, and don't go further than you need to
  • Don't disrupt the site or its visitors
  • Give us a reasonable time to fix the problem before you share details publicly

What you can expect from us

  • We'll acknowledge your report within 3 working days
  • We'll look into it, tell you whether we've confirmed it, and keep you updated on progress
  • We'll work to fix confirmed issues promptly, in proportion to how serious they are
  • If you'd like credit, we're happy to thank you by name once the issue is fixed. If you'd rather stay anonymous, we'll respect that
  • We won't take legal action against anyone who follows this policy in good faith

We're a small business and don't run a paid bug bounty programme, so we can't offer financial rewards.

Related information

How we handle personal data is explained in our Privacy Policy.