Responsible Disclosure Policy
Last updated 22 September 2026
SPEND PILOT LTD takes the security of SpendPilot and of our users' data seriously. If you believe you have found a security vulnerability in our website, apps or infrastructure, we want to hear from you, and this policy explains how.
1. Scope
In scope
- spendpilot.co.uk and its subdomains
- The SpendPilot apps for iOS and Android
- Our backend and APIs serving those apps
Out of scope
- Supermarket websites and apps. We do not own or control them. Report issues there to the supermarket.
- Third-party services we use, such as OpenAI, Google, Microsoft, Apple or our hosting provider. Report issues there to the provider concerned.
- Findings that require physical access to a user's device, social engineering of our staff or users, or denial of service.
- Reports from automated scanners with no demonstrated impact, missing best-practice headers with no exploit, and version disclosure alone.
2. How to report
Email [email protected] with the subject line "Security". Please include:
- what you found and where;
- steps to reproduce, with any proof of concept;
- the potential impact as you see it;
- how we can contact you, and whether you wish to be credited.
If you would like to encrypt your report, ask us for a PGP key at the same address. [PUBLISH A KEY FINGERPRINT HERE IF ONE IS AVAILABLE]
3. What we ask of you
- Do not access, change or delete data that is not yours. If you come across personal data, stop, do not keep it, and tell us.
- Do not run tests that could degrade the Service for other users.
- Do not test using accounts other than your own.
- Give us a reasonable time to fix the problem before disclosing it publicly. We ask for 90 days from your report, and we will work with you if we need longer.
- Act in good faith and within the law.
4. What you can expect from us
- Acknowledgement within 3 working days.
- An initial assessment within 10 working days.
- Regular updates while we work on a fix.
- Notification when the fix is released.
- Credit on this page, if you want it, once the issue is resolved.
We do not currently run a paid bug bounty programme.
5. Safe harbour
If you follow this policy and act in good faith, we will not take legal action against you or refer you to law enforcement for your research, and we will treat your research as authorised for the purposes of the Computer Misuse Act 1990 and equivalent laws. This does not apply to conduct outside this policy, or to anyone who exploits a vulnerability, extorts, or exposes user data.
6. Your personal data
We use the contact details you give us only to communicate with you about your report and, if you want, to credit you. We keep security reports for 3 years. See the Privacy Policy.
7. Not a security issue?
For general bugs, account problems and support, use [email protected] without the "Security" tag. For questions about how we handle personal data, use [email protected].
8. Contact
SPEND PILOT LTD, 128 City Road, London, United Kingdom, EC1V 2NX. Company number 17425596.
security.txt
The following should be served at https://spendpilot.co.uk/.well-known/security.txt.
Contact: mailto:[email protected]
Policy: https://spendpilot.co.uk/security
Preferred-Languages: en
Canonical: https://spendpilot.co.uk/.well-known/security.txt
Expires: 2027-09-22T00:00:00.000Z
The Expires value must be updated at least once a year.
Still have questions?
[email protected]