Security and responsible disclosure
Security Policy & Disclosure Guidelines
We take the security of our website, customer access, digital road trip guides and online planning platform seriously.
This page explains how to report a potential security issue to Uncover Britain responsibly, what information to include, and the testing behaviour we ask researchers to follow.
Report vulnerabilities
Please tell us promptly if you believe you have found a security issue affecting Uncover Britain.
Test responsibly
Do not damage systems, access customer data, interrupt services or publicly disclose issues before review.
Protect customer data
Avoid viewing, copying, changing, deleting or sharing personal data or member account information.
Use clear evidence
Send enough detail for us to understand and reproduce the issue safely without unnecessary data exposure.
Secure payment context
Payments are handled through third-party payment and platform providers. Never send payment card details by email.
Responsible disclosure
We value responsible reports and ask that you give us reasonable time to review and respond before public disclosure.
Uncover Britain Ltd
Last updated: 8 September 2025. Last reviewed: 18 June 2026.
1. How to report a security issue
If you believe you have discovered a security vulnerability affecting Uncover Britain, please report it by email.
Security reporting contact
Email: hello@uncoverbritain.com
Please include “Security report” in the subject line so your message can be identified quickly.
Please do not use social media, public comments, review platforms or other public channels to disclose a suspected vulnerability.
2. What to include in your report
To help us review your report safely and efficiently, please include as much of the following as you can:
- A clear description of the suspected vulnerability.
- The page, URL, account area, form or workflow affected.
- Steps needed to reproduce the issue.
- Browser, device and operating system information, where relevant.
- Screenshots or screen recordings, if they help explain the issue.
- The potential impact, in your view.
- Your contact details so we can follow up if needed.
Please avoid including personal data, payment information, customer account details or unnecessary sensitive information in your report.
3. Scope
This policy applies to security issues affecting Uncover Britain’s website, customer access experience, digital guide access routes and online content systems that are owned, controlled or operated by Uncover Britain.
Examples of potentially relevant reports may include:
- Unauthorised access to member-only content or customer account areas.
- Security issues affecting forms, login flows or customer access routes.
- Vulnerabilities that could expose customer data or private account information.
- Incorrect access controls affecting paid or private digital content.
- Significant configuration issues that could affect website or customer security.
4. Out of scope
Some reports are not normally considered security vulnerabilities for this policy, including:
- General content errors, broken links or spelling mistakes.
- SEO, analytics or marketing tracking observations that do not create a security risk.
- Issues affecting third-party websites that are not controlled by Uncover Britain.
- Automated scanner reports without evidence of real impact.
- Clickjacking or header findings without a clear practical risk.
- Social engineering, phishing attempts or physical security testing.
- Denial-of-service testing or performance stress testing.
- Reports requiring access to another person’s account or data.
5. Rules of engagement
When researching or reporting a potential issue, you must act responsibly and in good faith.
You must not:
- Access, copy, change, delete or disclose customer data.
- Access accounts, content or systems that you are not authorised to use.
- Interrupt, degrade or overload our website or services.
- Use destructive, automated or high-volume testing methods.
- Install malware, backdoors or persistent access methods.
- Attempt social engineering against customers, staff, suppliers or partners.
- Publicly disclose a vulnerability before we have had reasonable time to review and respond.
If you accidentally access personal data, private customer information or restricted content, stop testing immediately and tell us what happened.
6. Customer data and privacy
Customer privacy is important to us. Please do not intentionally access, view, copy, alter, delete or share personal data, member account information, payment-related information or private customer communications.
If your report involves personal data or account access, include only the minimum information needed for us to understand and investigate the issue.
For details about how we handle personal data, please read our Privacy Policy.
7. Response and fix timelines
We aim to acknowledge genuine security reports promptly and review them as quickly as reasonably possible.
Response and remediation timelines vary depending on severity, complexity, third-party platform involvement and the nature of the affected service.
Where a report affects third-party infrastructure, payment processing, hosting, membership access or embedded services, we may need to work with the relevant provider.
8. Public disclosure
Please do not publicly disclose suspected vulnerabilities until we have had reasonable time to investigate, respond and, where appropriate, apply a fix or mitigation.
We appreciate responsible disclosure that helps protect customers, members, partners and the wider website.
9. Third-party services
Uncover Britain uses third-party platforms and services for areas such as website hosting, payments, member access, analytics, forms, email and embedded tools.
If a vulnerability is clearly within a third-party service rather than Uncover Britain’s own configuration or customer experience, you should report it to the relevant provider through their own security process.
If you are unsure whether the issue affects Uncover Britain customers or access routes, please report it to us and explain the possible connection.
10. No reward programme
Uncover Britain does not operate a paid bug bounty or reward programme.
We are grateful for responsible reports, but we cannot guarantee payment, rewards, public acknowledgement or ongoing correspondence in every case.
11. Contact
For security reports, email hello@uncoverbritain.com.
For general customer support, guide access, order or website questions, please use our Contact page.
Need to report a security concern?
Email hello@uncoverbritain.com with “Security report” in the subject line.