Skip to content

Security Policy

Last updated: July 2026

We take the security of this website seriously - it is, after all, a site run by a security practice. If you believe you have found a vulnerability, we want to hear from you.

Reporting a Vulnerability

Please email vulnerability@elevelay.com with:

  • a description of the issue and where you found it;
  • the steps needed to reproduce it; and
  • what an attacker could do with it.

Please give us a reasonable chance to fix the issue before disclosing it publicly. A machine-readable version of this policy is published at /.well-known/security.txt, per RFC 9116.

What to Expect

We are a small practice, not a 24/7 security team, so these are honest targets rather than contractual commitments:

  • Acknowledgement of your report - within 3 working days.
  • Initial assessment - within 10 working days.
  • Fix or mitigation for a confirmed issue - as soon as practicable, prioritised by severity.

We are grateful for reports, and will happily credit you once an issue is resolved if you would like us to.

Scope

In scope: this website and its enquiry API - for example cross-site scripting, injection, authentication or authorisation flaws, server-side request forgery, and sensitive-data exposure.

Out of scope. Please do not report these, and please do not test them against the live site:

  • Volumetric denial-of-service or traffic-flooding attacks.
  • Automated scanner output with no demonstrated, exploitable impact.
  • Missing security headers or best-practice suggestions with no concrete attack.
  • Spam or abuse of the enquiry form itself - rate limiting and bot protection are known, deliberate trade-offs.
  • Social engineering of the practice or its providers, and physical attacks.
  • Vulnerabilities in third-party providers - please report those to the provider directly.

Safe Harbour

We will not pursue or support legal action against anyone who makes a good-faith effort to comply with this policy: who avoids privacy violations and service disruption, only interacts with accounts or data they own or have permission to test, and gives us a reasonable time to respond before any public disclosure. If you are unsure whether an action is acceptable, ask us first at the address above.

Contact

For any security question, email vulnerability@elevelay.com.