Skip to main content
Postcodewise logo
Responsible Disclosure & Safe Harbor

Vulnerability Disclosure Policy

At Digitsflow LTD, security and data integrity are fundamental to how we build Postcodewise. We value the vital contributions of independent security researchers, ethical hackers, and the wider cybersecurity community in identifying potential vulnerabilities through responsible, coordinated disclosure.

Last Updated: September 2026

1. Introduction & Commitment

Postcodewise is developed and operated by Digitsflow LTD (Company No. 16330711, registered in England & Wales, registered office: Suite A, James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE, United Kingdom).

We are committed to maintaining the highest security standards across our web applications, APIs, and open-data compilation pipelines. If you believe you have discovered a potential security vulnerability affecting our systems, services, or users, we encourage you to inform us immediately in accordance with this policy.

2. Safe Harbor & Legal Protection

Digitsflow LTD provides safe harbor protection for security researchers who act in good faith and comply with this policy.

We consider security research conducted strictly in accordance with this policy to be authorized under the Computer Misuse Act 1990, the Data Protection Act 2018 / UK GDPR, and other applicable computer fraud and abuse laws.

If you discover a vulnerability through good-faith research and report it in line with these terms:

  • We will not pursue civil claims, demand damages, or file a criminal complaint against you.
  • We will not initiate or support law enforcement investigations into your authorized research activities.
  • If legal action is threatened or initiated by a third party, we will openly confirm that your research was conducted with our authorization under this policy.

3. In-Scope Systems

This policy covers vulnerabilities identified within the following core systems and assets operated by Digitsflow LTD:

  • Public Website: postcodewise.co.uk and www.postcodewise.co.uk.
  • Developer REST APIs: api.postcodewise.co.uk and endpoints under /api/v1/*.
  • Workspace SaaS Surfaces: User authentication, surveys, CSV uploads, Postcode Intelligence keys, SiteScout analytics, and Floor Planner studio tools.
  • Browser Extensions: Official Postcodewise Property Report browser extension for Chromium, Firefox, and Safari.
  • Official SDKs & Widgets: Official Postcodewise WordPress plugin and embeddable scorecard widget.

4. Out-of-Scope & Prohibited Testing

To protect our users, infrastructure, and third-party partners, the following activities and systems are strictly out of scope:

  • Denial of Service (DoS / DDoS): Any attempt to disrupt service availability, exhaust memory/compute, or degrade latency for other users.
  • Volumetric Automated Scanning: Unthrottled automated scanning tools, fuzzing, or web crawling generating abusive traffic volumes.
  • Social Engineering & Phishing: Phishing, spear-phishing, vishing, or psychological manipulation targeting Digitsflow LTD employees, contractors, or customers.
  • Physical Security: Physical attacks, theft, or unauthorized access to our offices, data centres, or equipment.
  • Third-Party Processors & Infrastructure: Vulnerabilities within third-party providers (including Stripe checkout, AWS infrastructure, Cloudflare edge networks, or OpenStreetMap servers) must be reported directly to those vendors.
  • Data Modification or Exfiltration: Accessing, downloading, modifying, or deleting personal data, credentials, or workspace assets belonging to another account.

5. Responsible Research Guidelines

When testing for security vulnerabilities, researchers must abide by the following ethical standards:

  • Use Test Accounts: Perform security testing exclusively against accounts and workspaces you own or control. Do not attempt to access accounts belonging to other individuals or businesses.
  • Cease Testing upon Encountering Personal Data: If you inadvertently encounter personal, financial, or sensitive information during testing, halt testing immediately. Do not inspect, copy, screenshot, or transfer this data, and notify us immediately in your report.
  • Minimize Disruption: Conduct testing in a manner that does not affect service availability, performance, or integrity for regular users.
  • Maintain Confidentiality (Coordinated Disclosure): Do not disclose details of any suspected vulnerability publicly or to any third party until we have investigated, deployed a verified patch, and confirmed remediation.

6. How to Report a Vulnerability

To submit a vulnerability report, email our dedicated security team at:

[email protected]

Please include as much detail as possible to help us triage and reproduce the issue efficiently:

  • Summary: High-level overview of the issue, affected component, and potential security impact (e.g. OWASP category, CWE).
  • Reproduction Steps: Step-by-step instructions detailing how to reproduce the issue from an initial state.
  • Proof of Concept (PoC): Safe PoC code, sample HTTP request/response transcripts, or harmless demonstration payloads.
  • Environment Details: Browser version, operating system, and endpoint URLs involved.
  • Remediation Advice: Any recommended technical solutions or code modifications.

7. Our Response & Remediation SLAs

When you report a vulnerability in compliance with this policy, we commit to the following service level standards:

Initial Acknowledgment

We will acknowledge receipt of your report within 48 business hours.

Triage & Validation

We will complete technical validation and severity scoring within 5 business days.

Status Updates

We will provide transparent progress updates at least every 14 days until resolution.

Coordinated Disclosure

We operate a 90-day coordinated disclosure timeline, or shorter once a patch is verified in production.

8. Recognition & Hall of Fame

We do not currently operate a paid bug bounty program. However, for valid, qualifying vulnerability reports that are responsibly disclosed and resolved, we are delighted to offer public recognition on our Security Hall of Fame (listing your name, handle, or organization, subject to your explicit consent).

9. Machine-Readable Policy (RFC 9116)

In accordance with IETF RFC 9116, our machine-readable security contact metadata is published at:

https://postcodewise.co.uk/.well-known/security.txt

Governing Law: This policy and any related activities are governed by the laws of England and Wales.

© 2026 Digitsflow LTD. All rights reserved.

Detailed answer to your frequently asked question