Responsible Disclosure
If you have found a security vulnerability in CoverProof, we want to hear from you. This policy explains how to report it safely and what you can expect from us in return.
Last updated: 27 May 2026
If you have found a security vulnerability in CoverProof, we want to hear from you. This policy explains how to report it safely and what you can expect from us in return.
Last updated: 27 May 2026
Email security@coverproof.co.uk with a description of the issue, the steps to reproduce it, and its potential impact. Please give us reasonable time to investigate and fix the issue before any public disclosure.
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, will not pursue or support legal action against you for it, and will work with you to understand and resolve the issue quickly. If a third party brings legal action against you for activity that complied with this policy, we will make our authorisation known.
We will acknowledge your report, keep you updated as we investigate, and let you know when the issue is resolved. We do not currently run a paid bug-bounty programme, but we are glad to credit researchers who would like public recognition once an issue is fixed.