Choose which optional cookies and similar storage we may use. Strictly necessary storage is always on, because the site cannot work without it.

Draft: awaiting the Chief Technology Officer's review before publication

Vulnerability disclosure

If you think you have found a security vulnerability in something we run, please tell us at security@gateway-global.co.uk. We welcome reports and will work with you to fix what you find.

Last updated

Scope

gateway-global.co.uk, prime-assist.co.uk and averrahealth.ae.

Draft (F27): Confirm the scope, including our apps.

[TO CONFIRM: our apps]

Out of scope

  • Social engineering.
  • Denial of service.
  • Physical attacks.
  • Third-party services.

How to report

Email security@gateway-global.co.uk with the steps to reproduce the issue, its impact, and any proof of concept.

Access no more data than you need to show the issue, and delete anything you obtain.

Our commitments

  • We keep you updated while we investigate.
  • We fix issues according to their severity.
Draft (F27): How quickly we acknowledge a report (for example three working days).

We acknowledge every report within [TO CONFIRM].

Draft (F27): Safe harbour statement for good-faith research, approved by Legal Counsel.

Good-faith research

[TO CONFIRM: safe harbour statement]

Rewards

We do not run a bug bounty programme.