Security
Responsible disclosure policy
Nibblr Ltd holds recipes, formulations and commercial data that our customers have spent years developing. Protecting that is the whole job. We welcome reports from security researchers who find weaknesses in our platform, and this page sets out how to tell us.
There is no bounty
We do not run a paid bug bounty programme and we are not going to pretend otherwise. What we offer is a prompt reply from someone who can actually fix the problem, a straight answer on whether we consider it in scope, and our genuine thanks. If you would like public credit once a fix has shipped, ask and we will give it.
What is in scope
Anything we run on nibblr.co.uk, including subdomains. If you are not sure whether something belongs to us, ask before you test it.
The report needs to be original: something not already reported by someone else, and not already known to us from our own testing.
Please do not report the following. They are either not exploitable on their own or are accepted risks we have already weighed up.
- Volumetric attacks, meaning anything that works by overwhelming the service with traffic.
- TLS configuration opinions: cipher suite preferences, older protocol support, and the tool output that flags them.
- Missing security headers, or email configuration such as SPF and DMARC records, reported without a working exploit.
- Vulnerabilities that cannot be exploited, or that require an already-compromised device or browser.
- Reports that are only the output of an automated scanner, with no evidence the finding is real.
Rules of engagement
Test within these rules and we will treat your work as authorised research. Test outside them and we may treat it as an attack, which helps neither of us.
Respect other people's data. Do not attempt to access anyone's account or information. If you do gain access to data that is not yours, stop, tell us immediately at security@nibblr.co.uk, and do not save, copy or transmit any of it.
Take only what proves the point. Access the minimum needed to demonstrate the issue. Show us a proof of concept rather than extracting data.
Stop at the first finding and ask. Report it, then ask before continuing to test. Give us reasonable time to fix it before you tell anyone else.
While researching, please do not:
- Break the law, or any agreement you have with us or a third party.
- Disrupt the service for anyone else, including denial of service.
- Introduce malware, or modify, delete or corrupt any data.
- Change or disable any security control or configuration.
- Run brute-force or password-guessing attacks against accounts.
- Attempt social engineering against our staff, customers or suppliers, or any test of physical security.
- Give anyone else access to our systems, or share what you find with anyone other than us until a fix has shipped.
- Test anything outside the scope above.
Please also keep any data you do come across protected while you hold it, and delete it securely once your report is done.
How to report
Email security@nibblr.co.uk. The more of the following you can give us, the faster we can act:
- The URL or endpoint affected.
- What the vulnerability is, and what an attacker could do with it.
- The steps to reproduce it, including any proof of concept.
- Screenshots or a short recording, if they make it clearer.
- The IP address you tested from and roughly when, so we can find your activity in our logs.
- Your browser and operating system, where relevant.
- How you would like us to contact you, and whether you want credit.
If you can, mark your traffic with an
X-Security-Research header so we can tell it apart from a
real attack in progress.
What to expect from us
We are a small team, so these are commitments we can keep rather than the ones that read best:
- We will acknowledge your report within three working days.
- We will tell you whether we consider it in scope, and give you our assessment of the severity, within ten working days.
- We will keep you posted while we fix it, and tell you when it has shipped. You are welcome to ask how it is going; roughly once a fortnight is easiest for us.
- We will not take legal action against you for research conducted within this policy, and we will not ask you to sign anything before we will read your report.
Legal
This policy is written to sit alongside the law, not above it. It gives you no permission to act in a way that would breach legal or regulatory obligations, ours or yours, including the Computer Misuse Act 1990, the UK GDPR and Data Protection Act 2018, and the Copyright, Designs and Patents Act 1988.
Our approach follows ISO/IEC 29147 on vulnerability disclosure and ISO/IEC 30111 on the handling process behind it.
A machine-readable version of this contact information is published at /.well-known/security.txt, per RFC 9116.