In scope
Security weaknesses affecting Firearms Records-owned public websites, authenticated applications, APIs, account access, permissions, data boundaries, or service integrity are in scope.
Security disclosure
Firearms Records welcomes clear, responsible reports that help protect clubs, RFDs, shooters, and the integrity of the service. Please report suspected vulnerabilities privately before sharing details elsewhere.
Security weaknesses affecting Firearms Records-owned public websites, authenticated applications, APIs, account access, permissions, data boundaries, or service integrity are in scope.
Product suggestions, ordinary support requests, missing security headers without an exploitable impact, automated scan output without validation, and vulnerabilities that affect only unsupported third-party software should use the normal contact route instead.
Responsible testing
This policy supports good-faith reporting; it does not authorise unlawful access or waive legal rights. Keep testing proportionate to the minimum needed to demonstrate the issue.
A useful report
After you report
There is currently no paid bug-bounty programme. We will still handle responsible reports seriously and keep communication proportionate to the risk.
01
We aim to acknowledge a well-formed report within five working days.
02
We will assess reproducibility, severity, affected systems, and whether immediate containment is required.
03
Timelines depend on risk and complexity. We prioritise issues that could expose sensitive records, accounts, permissions, or service integrity.
04
Where practical, we will confirm the outcome after remediation or explain why the report was not treated as a security vulnerability.
Review the wider governance approach and the providers that support delivery of Firearms Records.