Last updated 23 September 2026. This page is the Policy target of /.well-known/security.txt.
Email [email protected]. Reports reach Desmond Odondiri of Elohim Solutions Ltd, who is the named security contact for this service and the person registered as its security contact in the UK Access Management Federation metadata.
Please include what you found, the exact steps to reproduce it, and what an attacker could do with it. A short proof of concept is worth more than a scanner report. Tell us if you would like to be credited.
We do not run a paid bug bounty. We say so plainly rather than leave it open: there is no reward beyond credit and our thanks.
Our suppliers run their own disclosure programmes and their infrastructure is not ours to authorise testing against. Report anything you find in the underlying platforms to the supplier, and tell us as well if it affects our data.
Safe harbour. If you follow this policy, act in good faith and stop at the first proof that a problem is real, we will treat your research as authorised, will not pursue legal action, and will not report you. We cannot waive the rights of our suppliers or of any third party, and this is not permission to access another person's data.
These are accepted with thanks but generally closed without a fix unless you can show real impact:
Personal data questions, subject access requests and data protection complaints go to [email protected], the route named in the Privacy Policy. This page is about security defects, not about the handling of your own data.