How to report
Email hello@wrexhamtechsupport.co.uk with the subject Security vulnerability report. Include the affected URL, a clear description, safe reproduction steps, likely impact and any supporting evidence that does not contain personal data.
We normally aim to acknowledge a credible report within three working days. Please give us a reasonable opportunity to investigate and address it before public disclosure.
Authorised scope
This policy applies only to the public website and systems that Wrexham Tech Support expressly identifies as in scope. It does not authorise testing of customer environments, supplier platforms, telephone systems, email accounts, social media accounts or any third-party service.
Safe research rules
To keep testing responsible, you must:
- Use only the minimum, non-destructive testing needed to demonstrate the issue.
- Stop immediately if you encounter personal, confidential or customer information, and do not retain or share it.
- Not disrupt availability, degrade performance, send spam, upload malware or conduct denial-of-service testing.
- Not use social engineering, phishing, physical intrusion, credential attacks or automated scanning that creates excessive traffic.
- Not change, delete, download or exfiltrate data, or establish persistence.
- Comply with applicable law and keep the report confidential while it is being investigated.
What you can expect
Where research is conducted in good faith, within this policy and without privacy or service impact, we will treat the report constructively and will not seek legal action solely because of that compliant research. This does not authorise unlawful activity or create permission on behalf of third parties.
We do not currently operate a paid bug-bounty programme. Recognition may be offered only where both parties agree and where doing so would not create additional risk.
Not usually a vulnerability
Reports limited to missing non-critical headers, automated scanner output without demonstrated impact, clickjacking on pages with no sensitive action, rate-limiting observations without exploitation, version disclosure, email spoofing claims without evidence, or issues requiring an already-compromised device may not require a security fix.
