Security
Vulnerability disclosure policy
Quarterwise holds tax records, so we want to hear about weaknesses before anyone else does. This page sets out what you may test, how we respond, and what we pay for valid reports.
Scope
The following are in scope:
- quarterwise.co.uk, including the signed-in app and its API
- Emails sent by Quarterwise, where the weakness is in something we control
The following are out of scope and reports about them will not be rewarded:
- Any subdomain other than quarterwise.co.uk itself
- Services we use but do not operate, such as Stripe, Postmark, Cloudflare and HMRC's own APIs. Report those to the provider.
- Social engineering of our staff or customers, physical attacks, and anything requiring a stolen device or credentials
Rules
Research within these rules is welcome. Research outside them is not, and forfeits the safe harbour below.
- Use your own account. Create one on the free plan; never test against an account you do not own.
- Never access, download, change or delete another person's data. If you find you can, stop and report it with the minimum evidence needed.
- No denial of service, no volume testing, and no automated scanning that puts noticeable load on the service.
- Do not run tests that send email or messages to people other than yourself.
- Keep what you find confidential until we have fixed it or 90 days have passed, whichever comes first.
Safe harbour
If you make a good-faith effort to follow these rules, we will treat your research as authorised. We will not pursue or support legal action against you for it, and if a third party begins action related to research done under this policy we will make it known that you acted within it. Where a report shows a personal data breach we will meet our own duties to the ICO and to affected customers, and we ask you to help by deleting any data you encountered.
What we do with a report
- Acknowledge it within two working days.
- Confirm the severity and tell you our plan within seven working days.
- Fix critical and high issues within 30 days, and other confirmed issues within 90.
- Tell you when the fix is live, and credit you on this page if you would like that.
Reports come to a small team, so you will hear from the person who is fixing it rather than a ticketing system.
Rewards
Rewards are paid for the first report of a confirmed, in-scope vulnerability with a working demonstration. Severity is judged by real-world impact on our customers' data and money, not by a scanner's rating. Where several reports describe the same root cause, the first is rewarded.
Amounts are in pounds sterling and paid by bank transfer within 30 days of the fix. We are a small company: these are thank-yous rather than market rates, and they are at our discretion.
What we do not reward
These are common findings that either carry no practical risk here or are already known. Please do not send them.
- Missing or “best practice” security headers, cookie flags or DNS records (SPF, DKIM, DMARC) without a demonstrated exploit
- Rate-limiting observations, username or email enumeration on the login and signup forms
- Clickjacking on pages with no state-changing actions
- Software version disclosure, verbose error pages, or output from automated scanners without proof of impact
- Self-XSS, or issues that need the victim to paste code into their own browser
- Weaknesses in browsers, operating systems or third-party services outside our control
- Theoretical issues with no reproducible demonstration
How to report
Use the security report form, or email security@quarterwise.co.uk. Include the URL or endpoint, steps to reproduce, the impact as you understand it, and how you would like to be credited. Our machine-readable contact details are published at /.well-known/security.txt.
Credit
Researchers who report a confirmed vulnerability are listed here with their name or handle if they wish. No reports have been credited yet.
Policy version 1, September 2026. Malden Ltd, trading as Quarterwise.