Vulnerability Disclosure Policy
If you think you've found a security problem on this website, we want to hear about it, and we'll treat you fairly for telling us.
Last updated: September 2026
Reporting a vulnerability
How to report
Email hello@yellanddigital.co.uk with "Security" in the subject line. Our machine-readable contact details are also published in our security.txt file.
Please include:
- A description of the issue and where you found it (the page or URL)
- The steps needed to reproduce it
- What you think the impact could be
- Any screenshots or proof-of-concept details that help us confirm it
Please don't include sensitive personal data in your report. If you need to share something private, tell us and we'll arrange a secure way to do it.
What's in scope
- The yellanddigital.co.uk website and its pages
- The contact form and the way it handles submitted data
What's out of scope
- Websites we've built or manage for clients. If you find something on a client site, please tell the site owner, or tell us and we'll pass it on
- Third-party services we use, such as Cloudflare, Microsoft Clarity and email providers. Please report those to the vendor directly
- Denial-of-service or load testing
- Social engineering, phishing, or physical attacks against us or anyone connected to us
- Spam, or automated scanner output submitted without checking that the issue is real
- Reports of missing best-practice headers or settings with no demonstrated impact
Please act in good faith
- Only test against your own data and accounts, and don't access, change or delete other people's data
- Stop as soon as you've shown the issue exists, and don't go further than you need to
- Don't disrupt the site or its visitors
- Give us a reasonable time to fix the problem before you share details publicly
What you can expect from us
- We'll acknowledge your report within 3 working days
- We'll look into it, tell you whether we've confirmed it, and keep you updated on progress
- We'll work to fix confirmed issues promptly, in proportion to how serious they are
- If you'd like credit, we're happy to thank you by name once the issue is fixed. If you'd rather stay anonymous, we'll respect that
- We won't take legal action against anyone who follows this policy in good faith
We're a small business and don't run a paid bug bounty programme, so we can't offer financial rewards.
Related information
How we handle personal data is explained in our Privacy Policy.