Home

Vulnerability disclosure policy

Last updated 23 September 2026. This page is the Policy target of /.well-known/security.txt.

Reporting a vulnerability

Email [email protected]. Reports reach Desmond Odondiri of Elohim Solutions Ltd, who is the named security contact for this service and the person registered as its security contact in the UK Access Management Federation metadata.

Please include what you found, the exact steps to reproduce it, and what an attacker could do with it. A short proof of concept is worth more than a scanner report. Tell us if you would like to be credited.

We do not run a paid bug bounty. We say so plainly rather than leave it open: there is no reward beyond credit and our thanks.

In scope

  • pathologylabtraining.co.uk and www.pathologylabtraining.co.uk. The web application and everything it serves, including the marketing pages, the learner application and the institutional dashboards.
  • wxfkdjusatdorfwbptsn.functions.supabase.co. Our own edge functions. The code is ours, so authorisation to test it is ours to give.
  • Our data model behind row level security. If you can read or change a record that belongs to another account or another organisation, we want to know immediately.
  • Our SAML service provider. The entity https://pathologylabtraining.co.uk/saml/sp, registered in the UK Access Management Federation, and the assertion consumer and logout endpoints it publishes.

Our suppliers run their own disclosure programmes and their infrastructure is not ours to authorise testing against. Report anything you find in the underlying platforms to the supplier, and tell us as well if it affects our data.

Rules of engagement

  • Use an account you created yourself. Do not access, modify, download or retain anybody else’s data. One record is proof; a dump is not.
  • Stop as soon as you have established that a problem is real, and tell us then rather than exploring how far it goes.
  • Do not run denial of service, volumetric, brute force or load testing of any kind against the live service.
  • Do not use social engineering, phishing or physical approaches against our staff, our customers or our suppliers.
  • Do not run automated scanners that degrade the service for other users, and do not spam our forms with test submissions.
  • Do not publish the finding, or share it outside your own team, until we have had a reasonable chance to fix it.
  • If you encounter personal data, stop, do not save it, and say so in your report.

What we commit to

Acknowledgement
Within 5 working days of your email, from a person rather than an autoresponder.
Triage
Within 10 working days we will tell you whether we have reproduced it and how we have rated it.
Progress updates
At least every 14 days while the report is open, until it is fixed or we explain why it will not be.
Credit
If you want it, we will name you when the fix ships. If you prefer to stay anonymous, that is the default.

Safe harbour. If you follow this policy, act in good faith and stop at the first proof that a problem is real, we will treat your research as authorised, will not pursue legal action, and will not report you. We cannot waive the rights of our suppliers or of any third party, and this is not permission to access another person's data.

Usually out of scope

These are accepted with thanks but generally closed without a fix unless you can show real impact:

  • Missing security headers, or a header set to a weaker value than you would choose, with no demonstrated exploit.
  • Output from an automated scanner pasted in without a working reproduction.
  • Self-inflicted cross-site scripting that requires the victim to paste code into their own browser console.
  • Rate limiting or the absence of a CAPTCHA, unless you can show a concrete impact beyond nuisance.
  • Software version disclosure, banner grabbing, or the existence of a login page that returns a generic error.
  • Clickjacking on a page that carries no state-changing action.
  • Email configuration findings for domains we do not send mail from.
  • Reports that depend on a browser, extension or operating system that is no longer supported by its vendor.

Personal data questions, subject access requests and data protection complaints go to [email protected], the route named in the Privacy Policy. This page is about security defects, not about the handling of your own data.