Coordinated vulnerability disclosure
Security
Reporting a vulnerability
Send reports to security@loric.uk. The same contact is published at /.well-known/security.txt so it can be found automatically.
Include the affected URL or component, the steps to reproduce, and what you were able to demonstrate. If a proof of concept touches data that is not yours, stop at the point the issue is demonstrated.
What we commit to
We acknowledge reports within one working day with a tracking reference. We give an initial triage outcome within five working days, and we keep you informed while remediation is in progress.
We will not pursue legal action against researchers acting in good faith under this policy, and we will credit you when a fix is published unless you ask us not to.
Scope
In scope: the Loric web application and its supporting API surfaces on loric.uk and its subdomains.
Out of scope: findings from automated scanners without a demonstrated impact, denial of service, social engineering, and issues in third-party services we do not operate.
How reports are handled
Reports enter a dedicated queue in the engineering ticket system with a named owner and a timer. Triage records severity and, separately, whether there is evidence of exploitation, because that distinction changes what we owe and to whom.
Once a fix is available we publish information about the resolved issue. We hold no bug bounty programme at present and say so rather than leaving it implied.
Our own practice
This page exists because a product whose flagship pattern is coordinated vulnerability disclosure cannot credibly ship without one of its own. It describes what we actually run, and we would rather narrow it than describe a process we do not operate.
Machine-readable: /.well-known/security.txt