Company · Security

Responsible disclosure.

If you have found a security issue in any BeyondTheBox surface, we want to know about it.

Contact

Email security@beyond-the-box.uk. We acknowledge within two working days. We will not pursue legal action against good-faith research.

What helps

  • A clear description of the issue and how to reproduce it.
  • The affected surface (URL, endpoint, or version).
  • Your suggested severity and any redacted proof-of-concept.

What we ask

  • Don't access data that isn't yours.
  • Don't run automated scans against production.
  • Give us reasonable time to fix before public disclosure.

security.txt

Machine-readable contact info is published at /.well-known/security.txt per RFC 9116.