security

Vulnerability Disclosure

How to report suspected vulnerabilities affecting DumDum Digital systems responsibly.

Effective
4 August 2026
Reviewed
4 August 2026

Contact

Send vulnerability reports to security@dumdumdigital.com. Do not send vulnerability details through social media or a public issue tracker. For particularly sensitive reports, contact us first so that an appropriate secure communication method can be agreed.

Scope

This policy covers dumdumdigital.com, subdomains operated directly by DumDum Digital and other systems that explicitly link to this policy. Client systems, third-party platforms, social media, physical premises, people and services operated by another organisation are outside scope unless expressly stated.

Permitted research

You may carry out proportionate good-faith testing intended to confirm whether a vulnerability exists, provided you test only in-scope systems and your own accounts or data, access no more information than necessary, stop if you encounter personal or confidential information, avoid disruption, persistence, malware, social engineering, denial of service, brute force or high-volume automated scanning, and allow a reasonable opportunity for investigation before disclosure.

What to include

Include the affected system, a clear description, reproduction steps, potential impact, safe supporting evidence, testing date and time, contact details and whether you would like to be credited. Do not include unnecessary personal information or data belonging to other users.

What you can expect

We aim to acknowledge reports within five working days, assess scope, request further information where needed, provide meaningful progress updates and confirm when an issue is resolved or closed. Complex issues and supplier dependencies may affect remediation time.

Good-faith research

Where you make a good-faith effort to comply with this policy, we will not initiate legal action solely for covered research. This does not provide immunity from law, bind third parties, authorise client-system access or excuse reckless, harmful, fraudulent or extortionate conduct.

Rewards and disclosure

DumDum Digital does not currently operate a paid bug-bounty programme. Please do not publicly disclose a vulnerability until we have had a reasonable opportunity to investigate and address it. Where disclosure is appropriate, we prefer to agree timing and content with the reporter.