UK Cybersecurity SpecialistsTransport·Logistics·Haulage·Warehousing SMEs
Security

Responsible Disclosure Policy

DefendVista welcomes reports from security researchers who help us keep our services, and our clients, safer. This page explains how to report a vulnerability, what we consider in scope, what to expect from us and the safe-harbour commitments we make to good-faith researchers.

Security contact: security@defendvista.com

How to report a vulnerability

Email security@defendvista.com with a clear description of the issue. Please use this address only for security reports: general enquiries should go through our contact page.

Include where possible:

  • The affected URL, endpoint or component.
  • A clear technical description of the issue and potential impact.
  • Steps to reproduce, including a proof of concept where appropriate.
  • Any logs, screenshots or request/response captures that support the report.
  • Your name or handle for acknowledgement, and a contact address.

If the issue is sensitive, you may request a PGP-encrypted reply channel in your initial email and we will arrange one.

What we consider in scope

In scope:

  • defendvista.com and www.defendvista.com
  • DefendVista-operated subdomains of defendvista.com
  • notify.defendvista.com email infrastructure
  • Public API endpoints under /api/*
  • Authentication, session handling, CSRF, SSRF, injection and access-control flaws
  • Sensitive-data exposure or PII leakage
  • Email authentication (SPF / DKIM / DMARC) misconfigurations

Out of scope:

  • Third-party SaaS or vendor systems we do not operate
  • Social engineering of staff, clients or suppliers
  • Physical attacks against premises or hardware
  • Denial-of-service, volumetric or stress testing
  • Reports generated solely by automated scanners with no demonstrated impact
  • Missing best-practice headers without a demonstrated exploit
  • Self-XSS, clickjacking on pages without sensitive state, and rate-limit-only findings

What to expect from us

  • Acknowledgement: within 1 UK working day.
  • Triage decision: within 5 UK working days.
  • Status updates: at least every 10 working days until resolution.
  • Remediation timeline: proportionate to severity: Critical issues are prioritised immediately.
  • Recognition: with your permission we will credit you publicly once the issue is resolved.

DefendVista does not currently operate a paid bug bounty programme. Reports are handled on a coordinated-disclosure basis.

Safe harbour

DefendVista will not pursue or support legal action against researchers who:

  • Act in good faith and follow this policy.
  • Make a genuine effort to avoid privacy violations, data destruction and service disruption.
  • Only interact with accounts they own or have explicit permission to test.
  • Stop testing and report immediately if they encounter user data, and do not retain, share or exploit it.
  • Give us a reasonable opportunity to remediate before public disclosure.

Activity consistent with this policy is considered authorised conduct and we will work with you to understand and resolve the issue quickly. If a third party brings legal action against you for activity consistent with this policy, we will make it known publicly that your actions were authorised.

Professional conduct

We ask researchers to behave professionally and respectfully throughout the disclosure process. Please do not:

  • Access, modify, exfiltrate or delete data that does not belong to you.
  • Use findings to extort, threaten or pressure DefendVista or our clients.
  • Publicly disclose the issue before we have had a reasonable opportunity to remediate.
  • Run intrusive automated scans that degrade availability for legitimate users.

Machine-readable policy

This policy is referenced from our /.well-known/security.txt file, in line with RFC 9116.

Last reviewed: 17 June 2026 · Expires: 17 June 2027.

Readiness ScoreBook Consultation