Changing LanesLimited

Legal

Vulnerability disclosure policy

How to report a security weakness to us safely, and what we promise in return.

Draft for legal review

This document has been prepared from the platform as it is built today and must be reviewed by a UK solicitor before it is relied on. Details marked [to be confirmed: …] are company details we are still confirming (1 in this document).
Version
1.0 (draft)
Effective date
Applies to
Security researchers
Owner and next review
Security lead · by
All legal documents

Our commitment

We want to hear about security weaknesses in the Changing Lanes platform so we can fix them quickly and protect the people who use it. If you report in good faith and follow this policy, we will not take legal action against you for your research and we will work with you to understand and fix the issue.

How to report

Email [to be confirmed: security contact email address] with:

  • the page or feature affected and what the weakness is;
  • the steps to reproduce it (screenshots help);
  • the impact you think it has;
  • how to contact you, if you would like updates or credit.

Our machine-readable contact details are also published at /.well-known/security.txt (RFC 9116).

Please do

  • give us reasonable time to fix the issue before telling anyone else — we suggest 90 days;
  • use only test accounts you create, or accounts you have permission to use;
  • stop as soon as you reach any personal data and tell us — do not copy, keep or share it.

Please do not

  • access, change or delete data that is not yours, or read other people's records;
  • run denial-of-service, load or spam tests, or social-engineering or physical attacks on our staff, learners, employers or premises;
  • use automated scanners at a rate that affects the service;
  • test third-party services we use (report issues in them to their owners).

What we will do

  • acknowledge your report within 5 working days;
  • keep you updated on our assessment and the fix;
  • tell you when it is resolved, and credit you if you wish.

We do not currently run a paid bug bounty. If personal data may have been exposed, we follow our breach procedure, which may include telling the Information Commissioner's Office within 72 hours.

Change history

Change history for Vulnerability disclosure policy
VersionDateChangeAcceptance needed again
1.0First draft for legal review, written from the platform as built.Yes — material change