Home / Security & disclosure

Security & disclosure

How to report a vulnerability to Grey Fox Labs, and how this site is protected.

Responsible disclosure

Reporting a vulnerability

We welcome reports from security researchers. If you believe you have found a vulnerability in a system operated by Grey Fox Labs, email [email protected] with enough detail for us to reproduce it.

Our commitments

  • We acknowledge reports within five working days.
  • We keep you informed while we investigate and fix.
  • We will not pursue legal action against research carried out in good faith within this policy.
  • We credit reporters who want to be credited.

In scope

  • This website and other services on greyfoxlabs.co.uk.

Out of scope

  • Denial-of-service, volumetric or resource-exhaustion testing.
  • Social engineering of staff, and physical attacks.
  • Third-party services we use (for example our hosting and payment providers). Report those to the provider.
  • Reports generated by automated scanners with no demonstrated impact.

Please

  • Use only the access needed to demonstrate the issue. Do not view, change or keep data that is not yours.
  • Give us reasonable time to fix an issue before you disclose it.

Machine-readable contact details are published at /.well-known/security.txt.

How this site is built

Static pages, no database, no login, no third-party scripts, no cookies. A strict content security policy, HSTS and frame protection are sent with every response.