Responsible Vulnerability Disclosure

Found a security issue in our site or systems? Here’s how to tell us safely.

Last updated: 30 September 2026 — reviewed annually.

Reporting a vulnerability

We welcome reports from independent security researchers. If you believe you have found a vulnerability in realcode.co.uk, our associated public web assets, or client demonstration systems we operate, please email contact@realcode.co.uk with the subject line “Security disclosure”.

A machine-readable version of this policy is published in the standard location at /.well-known/security.txt.

What to include

  • A description of the issue and the affected URL, asset or system.
  • Steps to reproduce, including any request/response evidence you gathered.
  • The potential impact, as you understand it.
  • Your contact details and, if you wish, a name we can credit.

In scope

  • This website and the public infrastructure we operate for it.
  • Client demonstration, staging or prototype systems we host under our control.

Third-party services we use but do not operate (for example our email or hosting providers) should be reported to those providers directly.

Safe harbour

If you act in good faith and within the rules below, we will not pursue or support legal action against you in relation to your research:

  • Do not access, modify or destroy data that is not yours — demonstrate issues with the minimum necessary interaction.
  • Do not disrupt our services or degrade availability (no denial-of-service testing).
  • Do not use social engineering, phishing or physical intrusion.
  • Keep the details confidential until we have had a reasonable opportunity to investigate and remediate.

What you can expect

  • We will acknowledge your report within five working days.
  • We will investigate, and where we confirm an issue we will remediate it in a timeframe proportionate to its severity.
  • With your permission we are happy to credit you once the issue is resolved. We are a small business and do not operate a paid bug-bounty programme.

Thank you for helping keep us — and our clients — secure.

Ready to talk about your project?

Tell Brad what you're building — you'll get a reply the same working day, plus a clear plan and a fixed quote in writing.