Skip to main content

Security disclosure

Report a suspected security vulnerability

Firearms Records welcomes clear, responsible reports that help protect clubs, RFDs, shooters, and the integrity of the service. Please report suspected vulnerabilities privately before sharing details elsewhere.

In scope

Security weaknesses affecting Firearms Records-owned public websites, authenticated applications, APIs, account access, permissions, data boundaries, or service integrity are in scope.

Not in scope

Product suggestions, ordinary support requests, missing security headers without an exploitable impact, automated scan output without validation, and vulnerabilities that affect only unsupported third-party software should use the normal contact route instead.

Responsible testing

Protect people and records while investigating

This policy supports good-faith reporting; it does not authorise unlawful access or waive legal rights. Keep testing proportionate to the minimum needed to demonstrate the issue.

  • Use only accounts and data that you own or have explicit permission to test.
  • Stop testing and report promptly if you encounter real customer data, credentials, or sensitive records.
  • Access only the minimum information needed to demonstrate the issue.
  • Do not disrupt availability, degrade the service, destroy or alter data, or attempt denial-of-service testing.
  • Do not use social engineering, phishing, spam, malware, physical attacks, or attacks against staff or suppliers.
  • Do not publish a suspected vulnerability before we have had a reasonable opportunity to investigate and remediate it.

A useful report

Include enough detail to reproduce it safely

  • The affected URL, hostname, API route, or product area.
  • A clear description of the suspected vulnerability and its potential impact.
  • Reproduction steps, a minimal proof of concept, and any relevant request or response details.
  • Whether you encountered personal data, customer records, credentials, or other sensitive information.
  • A safe way to contact you if we need clarification.

After you report

What to expect from Firearms Records

There is currently no paid bug-bounty programme. We will still handle responsible reports seriously and keep communication proportionate to the risk.

  1. 01

    Acknowledgement

    We aim to acknowledge a well-formed report within five working days.

  2. 02

    Triage

    We will assess reproducibility, severity, affected systems, and whether immediate containment is required.

  3. 03

    Remediation

    Timelines depend on risk and complexity. We prioritise issues that could expose sensitive records, accounts, permissions, or service integrity.

  4. 04

    Closure

    Where practical, we will confirm the outcome after remediation or explain why the report was not treated as a security vulnerability.

Related trust information

Review the wider governance approach and the providers that support delivery of Firearms Records.