Security & Vulnerability Disclosure

Last updated: 16 July 2026

The security of our customers' data is important to us. If you believe you've found a vulnerability or security issue with testedroutes.com, please tell us so we can fix it.

1. How to report

Email security@testedroutes.com with a description of the issue and step-by-step reproduction instructions. Where possible, include affected URLs, screenshots, and any relevant payload or request data. We aim to acknowledge your report within five business days.

2. Responsible disclosure

While we work on a fix, we ask that you:

3. Safe harbour

Where research is conducted in line with this policy, we consider it authorised. We will not pursue legal action against you for accessing our systems in good faith for the purpose of identifying and reporting a security issue.

4. Rewards

We do not run a paid bug-bounty programme, and no reward is guaranteed. For genuinely serious findings (e.g. authentication bypass, data exposure, payment manipulation) we may, at our sole discretion, offer a reward or recognition for responsible disclosure, decided case by case.

5. Out of scope

The following are generally not considered security vulnerabilities for the purposes of this policy: