Vulnerability Disclosure Policy
How to responsibly report a security vulnerability affecting our website or services.
Our Commitment
Drainage Protection Line Ltd takes the security of our website and customer data seriously. We welcome responsible disclosure of vulnerabilities by security researchers and the public, and we are committed to acknowledging and investigating every good-faith report.
1. Scope
This policy applies to the Drainage Protection Line Ltd website at www.drainageprotectionline.co.uk and any online services we operate. It does not apply to third-party websites or services we may link to.
2. How to Report a Vulnerability
Please report suspected vulnerabilities by email to info@drainageprotectionline.co.uk with the subject line “Vulnerability Disclosure”.
To help us investigate, please include:
- A clear description of the vulnerability and its potential impact
- The affected URL or service and the steps to reproduce the issue
- Any proof-of-concept, screenshots or supporting evidence
- Your name and contact details (optional, if you wish to be credited)
3. Our Response
We aim to acknowledge receipt of your report within 5 business days and to provide a substantive update on our investigation within 30 days. Where a vulnerability is confirmed, we will work to remediate it and, where appropriate, coordinate public disclosure with you.
4. Responsible Disclosure Guidelines
We ask that you:
- Provide reports in good faith and avoid accessing, modifying or destroying data that is not your own
- Do not attempt denial-of-service, social engineering of our staff, or physical attacks on our premises
- Do not access or exfiltrate other users’ personal data
- Avoid privacy violations and do not publicly disclose the vulnerability before we have had a reasonable opportunity to remediate it
5. Safe Harbour
We will not pursue legal action against individuals who report vulnerabilities in good faith and in accordance with this policy, provided their actions do not cause harm to our customers, our systems or our staff.
6. Out of Scope
The following are not considered vulnerabilities under this policy:
- Reports describing non-exploitable behaviour or theoretical risks without proof
- Brute-force, rate-limiting or credential-stuffing observations without demonstrated impact
- Vulnerabilities in third-party services or out-of-date software you do not control
- Issues requiring physical access to a user’s device
7. Contact & Company Details
Drainage Protection Line Ltd
Registered in England & Wales · Company No. 11871664
Registered Office: 71-75 Shelton Street, London, WC2H 9JQ
Email: info@drainageprotectionline.co.uk
Phone: 0800 949 6479
Report by Email
Subject line “Vulnerability Disclosure”.
Acknowledgement
Within 5 business days; substantive update within 30.
Good Faith
Safe harbour for responsible, lawful reporting.
Last Updated: September 2026
Version: 1.0