Security Policy

Camden Medicals takes the security of our website, applications, and customer data seriously. This page describes how to report a vulnerability and what you can expect from us in return.

Reporting a vulnerability

Email: [email protected]

Please include:

  • A clear description of the vulnerability
  • Steps to reproduce, or a proof of concept
  • The URL, endpoint, or component affected
  • Your contact details so we can follow up

If the issue affects customer personal data, you may copy our Data Protection Lead at [email protected].

What to expect from us

  • Acknowledgement of your report within 48 hours
  • A triage response with our assessment within 7 days
  • Regular updates while we investigate and remediate
  • Credit on this page once the issue is resolved, with your permission

Safe harbour

We will not pursue legal action against researchers who:

  • Make a good-faith effort to comply with this policy
  • Access, modify, or delete only the minimum data needed to demonstrate the issue
  • Do not perform testing that degrades the service for other users
  • Do not disclose the vulnerability publicly before we have had a reasonable opportunity to remediate

Out of scope

  • Denial-of-service or volumetric attacks
  • Social engineering of staff, customers, or suppliers
  • Physical security of our premises or hardware
  • Spam, phishing, or content-injection issues outside our application surface
  • Reports from automated scanners without demonstrated impact
  • Issues in third-party services we use (please report those to the relevant provider)

Bounty

We do not currently run a paid bug bounty programme. We may offer credit, recognition, or a token of appreciation at our discretion for high-impact reports.

Encrypted communication

If your report contains sensitive details, please request our PGP key by email and we will provide one for the exchange.


Last updated: 2 May 2026