Security & Vulnerability Disclosure

Last updated: 30 April 2026

The security of our customers' data is important to us. If you believe you've found a vulnerability or security issue with testedroutes.com, please tell us so we can fix it.

1. How to report

Email security@testedroutes.com with a description of the issue and step-by-step reproduction instructions. Where possible, include affected URLs, screenshots, and any relevant payload or request data. We will acknowledge your report within two business days.

2. Responsible disclosure

While we work on a fix, we ask that you:

3. Safe harbour

Where research is conducted in line with this policy, we consider it authorised. We will not pursue legal action against you for accessing our systems in good faith for the purpose of identifying and reporting a security issue.

4. Rewards

We do not run a paid bug-bounty programme by default. For genuinely serious findings (e.g. authentication bypass, data exposure, payment manipulation) we may, at our discretion, offer a reward or recognition for responsible disclosure. We will discuss any reward on a case-by-case basis.

5. Out of scope

The following are generally not considered security vulnerabilities for the purposes of this policy: