Vulnerability Disclosure Policy
Aligned with ISO/IEC 29147 and the UK NCSC Vulnerability Disclosure Toolkit. Aspire Connect welcomes reports from security researchers acting in good faith.
Scope
- The Aspire Connect web application and its published subdomains.
- Server APIs under
/api/. - Authentication, session, and role-based access controls.
Out of scope: denial-of-service, social engineering of staff, physical attacks, third-party services we do not operate.
How to report
Email security@aspireconnect.org.uk with a clear description of the issue, steps to reproduce, and any proof-of-concept. PGP encryption is available on request.
Our commitment
- Acknowledge receipt within 3 working days.
- Provide a triage assessment within 10 working days.
- Keep you informed of remediation progress.
- Credit reporters (with permission) on our security acknowledgements page.
Safe harbour
Researchers acting in good faith, respecting user privacy, and following this policy will not face legal action from Aspire Connect. Do not access, modify, or exfiltrate data beyond what is necessary to demonstrate the vulnerability. Never target real child, safeguarding, or SEN data.
Machine-readable
A signed policy is published at /.well-known/security.txt.