Annandale Websites

Responsible disclosure

If you have found a security problem in something we run, we would genuinely rather hear about it than not. Here is how to tell us, and what we will do about it.

Last updated: 2026

Scope

This policy covers annandalewebsites.com and the websites and infrastructure we host for our clients. If you are unsure whether something belongs to us, ask before testing — we will tell you either way.

How to report

Email [email protected] with “Security” in the subject line. Please include:

  • The affected URL, host or component.
  • What the issue is and what an attacker could do with it.
  • Enough detail to reproduce it — steps, a request, a proof of concept.
  • Any logs, screenshots or output that help.
  • How you would like to be credited, if at all.

Please report in English, and please report to us before anyone else.

What to expect from us

  • An acknowledgement within two working days.
  • An assessment and our view of the severity within ten working days.
  • Progress updates while we work on a fix, and a note when it is deployed.
  • Credit in any advisory we publish, if you would like it.

We ask for 90 days before public disclosure, and we will usually be finished well inside that. If a fix is going to take longer, we will tell you why rather than go quiet.

Safe harbour

If you act in good faith and follow this policy, we will not pursue legal action against you, and we will not report you to law enforcement. Acting in good faith means:

  • Only accessing the minimum data needed to demonstrate the issue, and stopping there.
  • Not modifying, deleting or exfiltrating anyone’s data.
  • Not degrading the service for anyone else.
  • Giving us reasonable time to fix the issue before telling anyone else about it.
  • Deleting any data you obtained once the report is closed.

If you are unsure whether a particular test crosses a line, ask first. We would rather answer a question than receive an apology.

Out of scope

These are things we already know about or have accepted, so please don’t spend your time on them:

  • Denial of service, volumetric or resource-exhaustion testing of any kind.
  • Social engineering, phishing or physical attacks against us, our clients or our suppliers.
  • Reports produced solely by an automated scanner, with no demonstrated impact.
  • Missing security headers, cookie flags or TLS configuration preferences with no working exploit.
  • Spam or content-injection issues that require an already-compromised account.
  • Vulnerabilities in third-party services we merely use, which should go to that vendor.

Recognition

We don’t run a paid bug bounty. What we do offer is a fast, human response, a real fix, and public credit if you want it.

Contact

[email protected] · 01865 689798 · Garbott Ltd, 13a Bankside, Kidlington, Oxfordshire OX5 1JE.