Reporting a Security Vulnerability

Garfield.Law Limited welcomes reports of security vulnerabilities in our website, application or API from security researchers, clients and other third parties. This page explains how to report one and what you can expect from us.

1. How to Report

Email security@garfield.law with:

  • a description of the issue and its potential impact;
  • the affected URL, endpoint or component;
  • steps to reproduce, with any proof-of-concept material;
  • whether you would like to be credited, and under what name.

Please do not include client or personal data in your report. If you need to send sensitive detail, ask for an encrypted channel in your first message and we will provide one.

2. What We Ask of You

  • Act in good faith and within the law.
  • Do not access, modify, download or retain data beyond what is needed to demonstrate the issue.
  • Do not disrupt the service or affect other users.
  • Do not use social engineering, phishing or physical attacks against our staff, offices or infrastructure.
  • Give us reasonable time to investigate and fix the issue before disclosing it publicly.

3. What Happens Next

We read every report and will acknowledge yours within 5 working days. We investigate confirmed issues on a timescale set by their severity, under the remediation targets in our internal information security policy, and will let you know when the issue is resolved.

We do not operate a paid bounty programme, but we are happy to credit reporters who wish to be named.

4. Legalities

This policy is designed to be compatible with common vulnerability disclosure good practice. It does not give you permission to act in any manner that is inconsistent with the law, or which might cause Garfield.Law Limited or its partner organisations to be in breach of any legal obligations.

5. Machine-Readable Contact

This page is referenced from our security.txt file, published in accordance with RFC 9116.