Skip to content

Security disclosure

Effective date: 19 September 2026

Scout Atlas Limited ("the Company") welcomes reports of possible security vulnerabilities on this website. Anyone who believes they have found one can report it to the contact details in clause 4, with enough detail to understand and reproduce the issue.

The Company will acknowledge every report within five working days, tell the reporter within ten working days whether it has confirmed the issue, and aim to fix a confirmed vulnerability within 90 days of the report. It will keep the reporter informed of progress and tell them when the fix is live. Reporters are asked not to publish details of a vulnerability until it has been fixed or until 90 days have passed since their report, whichever is sooner, unless the Company agrees a different date with them. There is no financial reward or bug bounty programme at this time, but the Company will credit a reporter by name on request once the issue is resolved.

This policy covers scoutatlas.uk and the subdomains the Company operates itself, including docs.scoutatlas.uk and umami.scoutatlas.uk. It does not cover the systems of the Company's service providers, such as Cloudflare or Hetzner, which the Company cannot authorise anyone to test, or any division's product or service that has its own disclosure policy.

The Company authorises good-faith security research within this scope on the following conditions: no denial-of-service, load or stress testing; no social engineering, phishing or physical attacks; no access to, copying, alteration or deletion of data beyond the minimum needed to show that a vulnerability exists; and immediate reporting, and no further access, if personal data or credentials are reached. Any data obtained must be deleted once the report is made and must not be shared with anyone else.

The Company will not bring legal proceedings, or refer to the police, anyone who complies with these conditions and reports promptly, and will treat such research as authorised for the purposes of the Computer Misuse Act 1990. This undertaking cannot bind third parties or the authorities, and it does not cover anyone who goes beyond these conditions.

Security reports should be sent by email to sharifhamza635@gmail.com. The same contact details are published in a machine-readable form at scoutatlas.uk/.well-known/security.txt.


The version of this notice published at scoutatlas.uk/security is the canonical and authoritative text; this page is a mirror of it.

Questions about this documentation can be sent to sharifhamza635@gmail.com.