Security reporting Responsible disclosure

Found a weakness?
Tell us safely.

We welcome good-faith reports that help protect Breachlight and its users. Please provide enough detail to reproduce the issue without including real leaked personal data.

How to report

Email the affected page, a concise description, reproduction steps, and the impact you believe is possible.

security@lukes.org.uk →

Please avoid

  • Accessing or changing another person’s data.
  • Denial-of-service testing, automated high-volume scanning, or social engineering.
  • Publishing an unresolved vulnerability before there has been a reasonable opportunity to investigate.
  • Sending passwords, live credentials, or breach contents in the report.

What to expect

We will review credible reports and aim to acknowledge them promptly. This page does not promise a bounty or create a contractual safe harbour, but good-faith, proportionate research is appreciated.

Machine-readable policy

Security tools can find the standard disclosure record at /.well-known/security.txt.