Vulnerability Disclosure Policy
Last updated: 17 August 2026
1. Introduction
Slink Group Limited ("Slink", "we", "us") takes the security of our products, services, and infrastructure seriously. We welcome reports from security researchers, customers, and members of the public who discover potential vulnerabilities.
This Vulnerability Disclosure Policy ("Policy") sets out how to report a vulnerability, what you can expect from us, and what we ask of you in return.
2. Scope
This Policy covers vulnerabilities in systems and services that Slink owns and operates, including:
- the Slink website (slink.co.uk and its subdomains);
- the Slink platform and customer-facing web applications;
- Slink-managed APIs and backend services; and
- any other digital service that is clearly identified as being operated by Slink.
The following are out of scope:
- third-party services or software that Slink does not control;
- social engineering, phishing, or physical attacks against Slink staff or offices;
- denial-of-service (DoS/DDoS) attacks;
- spam or unsolicited communications;
- vulnerabilities that require access to a victim's device or account; and
- issues without a demonstrable security impact (e.g. missing security headers that do not lead to exploitation).
3. How to Report
Please email your findings to security@slink.co.uk. To help us triage your report quickly, include:
- a clear description of the vulnerability and its potential impact;
- the affected URL, system, or component;
- step-by-step reproduction instructions;
- any proof-of-concept code, screenshots, or request/response captures; and
- your contact details (optional, but required if you would like updates on the report).
If you wish to encrypt your report, our PGP public key is available at /.well-known/security.txt.
4. Response SLA
We will acknowledge your report and keep you informed throughout the process:
- Acknowledgement: within 3 business days of receipt.
- Initial triage: within 10 business days. We will confirm whether the issue is within scope and provide an initial severity assessment.
- Remediation target: we aim to resolve confirmed critical vulnerabilities within 30 days and high-severity issues within 60 days. Complex or systemic issues may take longer; we will communicate any delays.
- Closure: we will notify you when the vulnerability has been remediated or when we have determined that no action is required.
5. Safe Harbour
Slink will not pursue civil or criminal action against researchers who discover and report security vulnerabilities in good faith and in accordance with this Policy. We consider security research conducted under this Policy to be:
- authorised under the Computer Misuse Act 1990 and equivalent legislation;
- conducted in good faith and for the benefit of the public interest; and
- exempt from restriction under our terms of service solely to the extent necessary to carry out the research.
Safe harbour applies provided you do not: access, modify, or delete data beyond what is strictly necessary to demonstrate the vulnerability; disclose the vulnerability publicly before we have had a reasonable opportunity to remediate it; or cause harm to Slink, its customers, or third parties.
6. Our Commitments
In return for responsible disclosure, Slink commits to:
- acknowledge your report promptly;
- keep you informed of our progress;
- work collaboratively with you to understand and resolve the issue;
- credit you in any public disclosure (if you wish and where appropriate); and
- not take legal action against you for good-faith research conducted under this Policy.
We do not currently operate a bug bounty programme offering financial rewards. This may change in the future.
7. What We Ask of You
We ask that researchers:
- make every effort to avoid privacy violations, data destruction, or service disruption;
- only interact with accounts and data you own or have explicit permission to test;
- do not retain, share, or exploit any data accessed during testing;
- report the vulnerability to us before disclosing it to any third party; and
- allow us a reasonable period to remediate before any public disclosure (coordinated disclosure).
8. Coordinated Disclosure
We believe in coordinated disclosure. Please give us a minimum of 90 days from the date of your report to investigate and remediate a confirmed vulnerability before publishing details publicly. If you intend to publish sooner, please let us know so we can discuss a timeline that protects users while respecting your research.
9. Contact
All security reports should be sent to security@slink.co.uk. For general enquiries, please use our contact page.
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected in the "Last updated" date above. We encourage researchers to review this Policy periodically.
Related: Privacy Policy · Terms of Use · Cookie Policy