Northmirrortier 1

Responsible disclosure

Report a vulnerability and we will work the issue with you — no lawyers, no silence.

Last updated: 31 Dec 2025

1. Scope

Everything under uk-mirror-01.bestaislop.com and the published API endpoints. Third-party services we merely link to are out of scope.

2. How to report

Email security@uk-mirror-01.bestaislop.com, encrypted with the PGP key referenced from /.well-known/security.txt. Include reproduction steps and the impact you believe it has.

3. What we promise

Acknowledgement within one business day, a triage decision within five, and a fix timeline you can hold us to. We will not pursue legal action against good-faith research that stays within scope and does not degrade the service for others.

4. Out of bounds

Denial of service testing, social engineering of staff or customers, physical attacks, and automated scanning that generates sustained load. Talk to us first if you need to test something noisy.

5. Recognition

With your permission we credit reporters in the changelog entry that carries the fix, and we pay a bounty scaled to severity.