Protection Research

Responsible Vulnerability Disclosure Policy

Effective Date: 3 August 2026

Contents

  • Purpose
  • Scope
  • Reporting a Vulnerability
  • Information to Include
  • Good Faith Security Research
  • Out of Scope Activities
  • Our Response Process
  • Coordinated Disclosure
  • Safe Harbour Statement
  • Contact

1. Purpose

Protection Research Ltd ("Protection Research", "we", "our" or "us") is committed to maintaining the security of our Services and protecting our customers' information. We recognise that independent security researchers can play an important role in identifying potential security vulnerabilities. This Responsible Vulnerability Disclosure Policy ("Policy") explains how security vulnerabilities affecting Protection Research systems should be reported and how we will work with researchers who act responsibly and in good faith. Our objective is to encourage responsible reporting while protecting our customers, our systems and the wider security community.

2. Scope

This Policy applies to vulnerabilities affecting systems, applications and online services owned or operated by Protection Research.

Examples include:

  • our public website
  • customer-facing applications

APIs;

  • authentication services
  • cloud-hosted systems under our control
  • publicly accessible infrastructure; and

other internet-facing services owned and operated by Protection Research.

This Policy does not apply to:

  • third-party services not controlled by Protection Research
  • vulnerabilities affecting customer-managed systems
  • vulnerabilities already publicly known
  • social engineering attacks against our personnel
  • physical security testing; or

attacks against third-party suppliers.

3. Reporting a Vulnerability

If you believe you have identified a security vulnerability affecting Protection Research, please report it as soon as reasonably practicable.

Reports should be submitted by email to:

  • support@protectionresearch.com
  • Please use the subject line:

Responsible Vulnerability Disclosure

We request that vulnerabilities are reported privately and are not publicly disclosed until we have had a reasonable opportunity to investigate and remediate the issue.

4. Information to Include

  • To assist our investigation, vulnerability reports should include, where possible:
  • a clear description of the vulnerability
  • the affected system or service
  • steps required to reproduce the issue
  • proof of concept where appropriate
  • potential impact
  • relevant URLs or endpoints
  • screenshots or supporting evidence where available
  • software versions where relevant; and

contact details for follow-up questions. Providing clear and reproducible information helps us investigate and resolve reported issues more efficiently.

5. Good Faith Security Research

Protection Research welcomes responsible security research conducted in good faith.

Researchers acting responsibly should:

  • avoid causing disruption to our Services
  • avoid accessing unnecessary information
  • stop testing immediately after confirming a vulnerability
  • avoid modifying or deleting data
  • avoid affecting the availability of our systems
  • keep vulnerability information confidential until disclosure is agreed; and

comply with all applicable laws. We ask researchers to act in a manner that minimises risk to our customers and business operations.

6. Out of Scope Activities

  • The following activities are not authorised under this Policy:
  • denial-of-service or distributed denial-of-service attacks
  • phishing or social engineering
  • malware deployment
  • ransomware or extortion
  • physical intrusion attempts
  • credential stuffing or password spraying
  • brute-force attacks
  • spam or unsolicited communications
  • exploitation of vulnerabilities after confirmation
  • accessing, copying, modifying or deleting customer data without authorisation
  • persistence within our systems
  • privilege escalation beyond what is necessary to demonstrate a vulnerability; or

any activity that disrupts the availability, confidentiality or integrity of our Services. Researchers must immediately cease testing if there is a risk of impacting production systems or customer data.

7. Our Response Process

Protection Research appreciates the time and effort invested by security researchers in helping us improve the security of our Services. Upon receiving a vulnerability report, we aim to: acknowledge receipt of the report within a reasonable period; assess whether the reported issue falls within the scope of this Policy; investigate the reported vulnerability; determine the potential impact and severity; develop and implement appropriate remediation measures where necessary; keep the reporting researcher informed of material progress where reasonably practicable; and notify the researcher when the vulnerability has been resolved or otherwise addressed. Response times may vary depending on the complexity, severity and potential impact of the reported issue. Protection Research reserves the right to prioritise remediation activities based on risk to customers, systems and business operations.

8. Coordinated Disclosure

Protection Research supports the principle of coordinated vulnerability disclosure. We request that researchers do not publicly disclose vulnerability details until: we have confirmed that appropriate remediation has been implemented; customers have had a reasonable opportunity to apply any necessary updates or mitigations; or we have otherwise agreed an appropriate disclosure timeline with the reporting researcher. Where appropriate, we may publicly acknowledge researchers who have responsibly disclosed vulnerabilities, subject to their consent. Protection Research does not currently operate a bug bounty or financial reward programme, and the submission of a vulnerability report does not create any entitlement to compensation or other remuneration.

9. Safe Harbour Statement

Protection Research will not pursue legal action against individuals who:

  • act in good faith
  • comply with this Policy
  • make reasonable efforts to avoid privacy violations, service disruption and data destruction
  • promptly report identified vulnerabilities
  • cease testing once a vulnerability has been confirmed; and

do not exploit vulnerabilities beyond what is reasonably necessary to demonstrate their existence.

This Safe Harbour Statement applies only to activities that are:

  • lawful
  • authorised by this Policy; and

conducted in a responsible and ethical manner. Nothing in this Policy authorises activities that are unlawful or that violate the rights of Protection Research, our customers, our suppliers or any third party. Protection Research reserves the right to refer matters to the appropriate authorities where activities are malicious, unlawful, reckless or fall outside the scope of this Policy.

10. Contact

Questions or vulnerability reports relating to this Policy should be directed to:

Protection Research Ltd

Company Number: 17366537

Registered Office: 41 Colwyn Road, Stockport, Cheshire, England, SK7 2JG

Email: support@protectionresearch.com

Subject Line: Responsible Vulnerability Disclosure

End of Responsible Vulnerability Disclosure Policy

Effective Date: 3 August 2026

© Protection Research Ltd. All rights reserved.