Vulnerability Disclosure Policy
Vulnerability Disclosure Policy
Bud welcomes reports of security vulnerabilities in our services. If you believe you have found a vulnerability, please tell us using the process below. We will work with you to understand and resolve it.
We do not operate a paid bug bounty programme and we do not offer financial rewards for reports. We will, with your permission, credit researchers who report valid issues.
Reporting a vulnerability
Email security@bud.co.uk.
Please include:
- The affected URL, hostname or API endpoint
- The vulnerability type and a brief description of the impact
- Clear steps to reproduce, including any request/response samples or proof-of-concept code
- The date and time of your testing, and the source IP address(es) you tested from
- Whether you believe any personal data was exposed
- How you would like to be credited, if at all
Please report in English. One issue per report, where practical.
Do not report vulnerabilities through our commercial support channels, sales contacts, or social media accounts.
Scope
In scope
bud.co.ukbudmark.co.ukand their subdomains- The Bud learner management platform and associated APIs
- The Bud Mark platform and associated APIs
Out of scope
- Systems operated by our customers, including customer-managed identity providers, single sign-on configurations and integrations
- Third-party services we consume (for example cloud infrastructure, payment providers, email providers). Please report these to the relevant provider under their own disclosure policy.
- Systems hosted on government or client-owned domains, including systems delivered under government programmes. These are covered by the disclosure processes of the relevant contracting authority and are not covered by this policy.
- Any Bud system to which you have been granted contractual access for penetration testing. That work is governed by the terms of the relevant engagement, not this policy.
If you are not sure whether something is in scope, email us and ask before testing.
Authorisation
If you make a good-faith effort to comply with this policy while researching a vulnerability in a system that is in scope, we will:
- Treat your research as authorised access for the purposes of the Computer Misuse Act 1990
- Not initiate or support legal action against you in relation to that research
- Work with you to understand and resolve the issue
This authorisation is limited to systems Bud Systems operates and to activity consistent with this policy. We cannot authorise access to systems belonging to our customers, our suppliers, or any third party, and nothing in this policy grants you permission in respect of those systems.
If legal action is initiated by a third party against you in relation to activity conducted in accordance with this policy, we will make this authorisation known to that party on request.
If you are unsure whether an action is permitted, stop and contact us first. We would far rather answer a question in advance than deal with the consequences afterwards.
Rules of engagement
You must not:
- Access, modify, download, retain or delete data belonging to any other user, learner, employer or customer
- Attempt to gain access to any account other than one you own or have explicit written permission to test
- Conduct denial-of-service or resource-exhaustion testing, or any activity likely to degrade service for others
- Send high-volume automated scans or brute-force traffic against our systems
- Use social engineering, phishing or pretexting against our staff, our customers, our learners or our suppliers
- Attempt physical access to our premises or equipment
- Install malware, backdoors or persistence mechanisms
- Exploit a vulnerability further than is necessary to demonstrate that it exists
- Disclose the vulnerability to anyone else before we have resolved it, other than as set out below
Where possible, please test against your own account. If you need a test account to investigate an issue safely, contact us and we will consider providing one.
Personal data — stop immediately
Our platform holds personal data about learners in education and training, including safeguarding information and data relating to people under the age of 18.
If, at any point in your testing, you access or are able to view personal data belonging to anyone other than yourself:
- Stop testing immediately. Do not continue to confirm the extent of the exposure.
- Do not download, copy, screenshot, retain or share the data. A description of what you saw is sufficient for us to act.
- Report it to us straight away, describing the type of data and the approximate volume, without including the data itself.
- Securely delete any data you have inadvertently retained, and confirm to us that you have done so.
This applies with particular force to any vulnerability that allows data to be viewed across customer boundaries. Demonstrating that one record is reachable is enough. Enumerating further is not necessary, is not authorised, and may trigger our own breach-notification obligations far beyond what the finding requires.
We will not treat an accidental, promptly reported and properly deleted exposure as a breach of this policy.
What you can expect from us
| Stage | Target |
|---|---|
| Acknowledgement of your report | [3] working days |
| Initial assessment and validity decision | [10] working days |
| Progress updates thereafter | Every [15] working days until resolved |
We will:
- Tell you whether we consider the report valid, and explain our reasoning if we do not
- Keep you informed of remediation progress
- Confirm when the issue is resolved
- Credit you publicly if you wish, once the issue is resolved
Remediation timescales depend on severity and complexity. We will give you an indicative timeline once we have triaged the report, and we will tell you if it slips.
Reports are handled in business hours, Monday to Friday, excluding UK public holidays.
Coordinated disclosure
We ask that you give us a reasonable opportunity to fix an issue before disclosing it publicly. Our default expectation is 90 days from the date we acknowledge your report, or the date the issue is resolved, whichever is earlier.
If you intend to publish, please tell us in advance so we can coordinate. We will not ask you to delay indefinitely, and we will tell you if we need longer and why. If we cannot agree, we would rather have that conversation openly than discover a publication after the fact.
Please do not include customer names, learner data, screenshots containing personal data, or internal hostnames in any public write-up.
Reports we are unlikely to act on
The following are generally not accepted without a working proof of concept demonstrating real impact:
- Missing or misconfigured HTTP security headers
- Missing SPF, DKIM or DMARC records, or policy strength opinions, where no spoofing is demonstrated
- TLS configuration and cipher-suite findings with no demonstrated exploit
- Software or framework version disclosure, banner grabbing, and other fingerprinting
- Self-XSS, or issues requiring the victim to paste content into their own browser console
- Clickjacking on pages with no sensitive state-changing action
- Absence of rate limiting on endpoints that do not perform authentication or state change
- Content spoofing or text injection with no HTML or script execution
- Issues affecting only end-of-life browsers or operating systems
- Vulnerabilities requiring a compromised device, physical access, or a rooted or jailbroken device
- Unvalidated output from automated scanning tools
- Descriptions of theoretical risk with no evidence of exploitability
- Reports concerning our marketing website's third-party analytics or content delivery, absent a demonstrated compromise
We may still fix these. We will not usually credit them.
Confidentiality and your data
We will treat your report as confidential and will not share your identity outside Bud Systems without your consent, except where we are legally required to do so or where doing so is necessary to protect affected individuals.
We will process the personal data you give us (your name, email address and the content of your report) for the purpose of managing and resolving the report. Our privacy notice is available at Legal and regulatory information.
If we need to notify a customer or a regulator about an issue you have reported, we will normally do so without identifying you unless you agree otherwise.
Changes to this policy
This policy is reviewed at least annually and after any material change to our services or disclosure process. Last modified Audust 2026.
Machine-readable contact details are published at https://bud.co.uk/.well-known/security.txt in accordance with RFC 9116.
Contact
For matters unrelated to security vulnerabilities — including data protection requests, product support and commercial enquiries — please use the contact routes on our main website. Reports sent to this address that are not security vulnerability reports will be redirected and may not receive a response.