Security

Vulnerability disclosure policy

Quarterwise holds tax records, so we want to hear about weaknesses before anyone else does. This page sets out what you may test, how we respond, and what we pay for valid reports.

Scope

The following are in scope:

  • quarterwise.co.uk, including the signed-in app and its API
  • Emails sent by Quarterwise, where the weakness is in something we control

The following are out of scope and reports about them will not be rewarded:

  • Any subdomain other than quarterwise.co.uk itself
  • Services we use but do not operate, such as Stripe, Postmark, Cloudflare and HMRC's own APIs. Report those to the provider.
  • Social engineering of our staff or customers, physical attacks, and anything requiring a stolen device or credentials

Rules

Research within these rules is welcome. Research outside them is not, and forfeits the safe harbour below.

  • Use your own account. Create one on the free plan; never test against an account you do not own.
  • Never access, download, change or delete another person's data. If you find you can, stop and report it with the minimum evidence needed.
  • No denial of service, no volume testing, and no automated scanning that puts noticeable load on the service.
  • Do not run tests that send email or messages to people other than yourself.
  • Keep what you find confidential until we have fixed it or 90 days have passed, whichever comes first.

Safe harbour

If you make a good-faith effort to follow these rules, we will treat your research as authorised. We will not pursue or support legal action against you for it, and if a third party begins action related to research done under this policy we will make it known that you acted within it. Where a report shows a personal data breach we will meet our own duties to the ICO and to affected customers, and we ask you to help by deleting any data you encountered.

What we do with a report

  • Acknowledge it within two working days.
  • Confirm the severity and tell you our plan within seven working days.
  • Fix critical and high issues within 30 days, and other confirmed issues within 90.
  • Tell you when the fix is live, and credit you on this page if you would like that.

Reports come to a small team, so you will hear from the person who is fixing it rather than a ticketing system.

Rewards

Rewards are paid for the first report of a confirmed, in-scope vulnerability with a working demonstration. Severity is judged by real-world impact on our customers' data and money, not by a scanner's rating. Where several reports describe the same root cause, the first is rewarded.

SeverityExamplesReward
CriticalAccess to another user’s HMRC tokens, National Insurance number or transactions; remote code execution; full account takeover without user interaction.£500
HighAuthentication or two-factor bypass; reading or changing another account’s data; privilege escalation to admin.£250
MediumStored cross-site scripting; insecure direct object references on non-sensitive data; CSRF on a state-changing action.£100
LowReflected cross-site scripting requiring unusual user interaction; minor information leaks.Our thanks and public credit

Amounts are in pounds sterling and paid by bank transfer within 30 days of the fix. We are a small company: these are thank-yous rather than market rates, and they are at our discretion.

What we do not reward

These are common findings that either carry no practical risk here or are already known. Please do not send them.

  • Missing or “best practice” security headers, cookie flags or DNS records (SPF, DKIM, DMARC) without a demonstrated exploit
  • Rate-limiting observations, username or email enumeration on the login and signup forms
  • Clickjacking on pages with no state-changing actions
  • Software version disclosure, verbose error pages, or output from automated scanners without proof of impact
  • Self-XSS, or issues that need the victim to paste code into their own browser
  • Weaknesses in browsers, operating systems or third-party services outside our control
  • Theoretical issues with no reproducible demonstration

How to report

Use the security report form, or email security@quarterwise.co.uk. Include the URL or endpoint, steps to reproduce, the impact as you understand it, and how you would like to be credited. Our machine-readable contact details are published at /.well-known/security.txt.

Credit

Researchers who report a confirmed vulnerability are listed here with their name or handle if they wish. No reports have been credited yet.

Policy version 1, September 2026. Malden Ltd, trading as Quarterwise.