Our commitment
We want to hear about security weaknesses in the Changing Lanes platform so we can fix them quickly and protect the people who use it. If you report in good faith and follow this policy, we will not take legal action against you for your research and we will work with you to understand and fix the issue.
How to report
Email [to be confirmed: security contact email address] with:
- the page or feature affected and what the weakness is;
- the steps to reproduce it (screenshots help);
- the impact you think it has;
- how to contact you, if you would like updates or credit.
Our machine-readable contact details are also published at /.well-known/security.txt (RFC 9116).
Please do
- give us reasonable time to fix the issue before telling anyone else — we suggest 90 days;
- use only test accounts you create, or accounts you have permission to use;
- stop as soon as you reach any personal data and tell us — do not copy, keep or share it.
Please do not
- access, change or delete data that is not yours, or read other people's records;
- run denial-of-service, load or spam tests, or social-engineering or physical attacks on our staff, learners, employers or premises;
- use automated scanners at a rate that affects the service;
- test third-party services we use (report issues in them to their owners).
What we will do
- acknowledge your report within 5 working days;
- keep you updated on our assessment and the fix;
- tell you when it is resolved, and credit you if you wish.
We do not currently run a paid bug bounty. If personal data may have been exposed, we follow our breach procedure, which may include telling the Information Commissioner's Office within 72 hours.
Change history
| Version | Date | Change | Acceptance needed again |
|---|---|---|---|
| 1.0 | First draft for legal review, written from the platform as built. | Yes — material change |