Camden Medicals takes the security of our website, applications, and customer data seriously. This page describes how to report a vulnerability and what you can expect from us in return.
Reporting a vulnerability
Email: [email protected]
Please include:
- A clear description of the vulnerability
- Steps to reproduce, or a proof of concept
- The URL, endpoint, or component affected
- Your contact details so we can follow up
If the issue affects customer personal data, you may copy our Data Protection Lead at [email protected].
What to expect from us
- Acknowledgement of your report within 48 hours
- A triage response with our assessment within 7 days
- Regular updates while we investigate and remediate
- Credit on this page once the issue is resolved, with your permission
Safe harbour
We will not pursue legal action against researchers who:
- Make a good-faith effort to comply with this policy
- Access, modify, or delete only the minimum data needed to demonstrate the issue
- Do not perform testing that degrades the service for other users
- Do not disclose the vulnerability publicly before we have had a reasonable opportunity to remediate
Out of scope
- Denial-of-service or volumetric attacks
- Social engineering of staff, customers, or suppliers
- Physical security of our premises or hardware
- Spam, phishing, or content-injection issues outside our application surface
- Reports from automated scanners without demonstrated impact
- Issues in third-party services we use (please report those to the relevant provider)
Bounty
We do not currently run a paid bug bounty programme. We may offer credit, recognition, or a token of appreciation at our discretion for high-impact reports.
Encrypted communication
If your report contains sensitive details, please request our PGP key by email and we will provide one for the exchange.
Last updated: 2 May 2026