Security & Responsible Disclosure
Last updated: 23/07/2026
Autodue Ltd ("we", "us", or "our") takes the security of our customers' data seriously. We welcome reports from security researchers and anyone who finds a vulnerability in our website, web application, mobile apps, or API. This page explains how to report a security issue, what is in scope, what to expect after you report, and the protections we offer for good-faith research.
1. How to Report
Email us at [email protected] with the details of what you found. This is the same contact listed in our security.txt. To help us reproduce and fix the issue quickly, please include:
- A clear description of the vulnerability and its potential impact.
- The steps to reproduce it, including the affected URL, endpoint, or screen.
- Any proof-of-concept requests, payloads, or screenshots.
- The account(s) you used, so we can correlate the activity in our logs.
2. Scope
The following are in scope for reports:
- The website and web application at autodue.co.uk.
- The Autodue mobile apps (iOS and Android).
- The Autodue API consumed by those apps.
3. Out of Scope
The following are generally not eligible and do not need to be reported:
- Denial-of-service (DoS/DDoS) attacks, volumetric testing, or automated request floods.
- Social engineering, phishing, or physical attacks against our staff, users, or offices.
- Reports from automated scanners without a demonstrated, exploitable impact.
- Missing security headers or best-practice recommendations with no demonstrated impact.
- Rate-limiting or brute-force concerns without a working proof of concept.
- Vulnerabilities in third-party services we do not control.
4. What to Expect
We aim to acknowledge your report within 5 working days, keep you updated as we investigate, and let you know when the issue is resolved. We do not currently run a paid bug-bounty programme, but we are grateful for every responsible report and are happy to credit researchers who wish to be acknowledged.
5. Guidelines for Researchers
When testing, please:
- Use your own test accounts. Do not access, modify, or store other users' data.
- Stop as soon as you have confirmed a vulnerability, and do not exfiltrate more data than needed to demonstrate it.
- Avoid actions that degrade, disrupt, or damage our services or data.
- Give us reasonable time to investigate and fix the issue before disclosing it publicly.
6. Safe Harbour
If you make a good-faith effort to comply with this policy during your research, we will consider it authorised, will not pursue or support legal action against you for it, and will work with you to understand and resolve the issue quickly. If a third party brings legal action against you for activity conducted in line with this policy, we will make it known that your actions were authorised.