Vulnerability disclosure
Controlled document: ACC-DOC-SECURITY (decision ACC-SECURITY-001)
Candidate version: 0.3
Production scope: fndguide.co.uk and www.fndguide.co.uk. Netlify serves
the static site; Fasthosts retains DNS and email. The live custom domain,
HTTPS certificate, security headers and www redirect passed their public
checks on 5 August 2026.
Reporting a security problem
If you find a security vulnerability in this site, thank you — please tell us privately before telling anyone else.
- Contact: security@fndguide.co.uk — a dedicated forwarder into the FND Guide mailbox. Mark security reports clearly in the subject line.
- Secure option: none is offered at this scale; this is stated plainly rather than pretended.
- Monitored by: the project owner. This is a one-person project: there is no out-of-hours cover, and acknowledgement may take up to 7 days (availability boundary, 17 July 2026).
- If the route is unavailable: use hello@fndguide.co.uk with “SECURITY” at the start of the subject. If the whole mailbox service is unavailable, the site change log will record a temporary route when the owner can safely provide one.
- Last external delivery test: 2 August 2026. The security forwarder and direct mailbox received external tests, and the reply path passed SPF, DKIM and DMARC.
Scope
- In scope: the public website at fndguide.co.uk and the
wwwhostname. It is a static, pre-rendered site with no accounts, no login, no databases and no user-generated content, which keeps the attack surface deliberately small. - Out of scope: the hosting provider's own infrastructure (report to them), external sites we link to, and any system not listed here.
What we expect from researchers
Act lawfully and in good faith: do not access, alter or destroy data that is not yours; do not degrade the service for others (no denial-of-service or volumetric testing); do not run social-engineering or phishing attacks against anyone connected to the project; stop and report as soon as you can demonstrate an issue.
In a report, it helps to include: the URL or component, steps to reproduce, what you observed, and how to contact you for follow-up.
What you can expect from us: acknowledgement within the window above, an honest assessment, a fix or documented mitigation as fast as one person can responsibly manage, credit if you want it once resolved (or anonymity if you prefer), and no legal action against good-faith research within this policy. There is no monetary reward programme.
Any personal data in a report is used only to handle the report and is deleted afterwards — see the privacy notice.
security.txt
- Location:
https://fndguide.co.uk/.well-known/security.txt(also reachable through the coveredwwwredirect). Contact:mailto:security@fndguide.co.uk.Policy:https://fndguide.co.uk/security/.Canonical:https://fndguide.co.uk/.well-known/security.txt.Expires:2027-08-05T00:00:00Z; it must be renewed before that time.- Deployment and retrieval test: included in this correction release and must pass on the exact deploy preview and public domain before the release closes.
- Renewal owner: project owner.
The right route for other problems
- Something on a page is wrong or unsafe: the corrections route.
- A complaint about the project: the complaints route.
- A personal medical or emergency concern: this site cannot help urgently — use NHS 111, or 999 in an emergency.
- A security vulnerability: this route.
Review record
- Security owner: project owner / 5 August 2026, controlled successor version 0.3.
- Data-protection advice: not obtained.
- Production-host checks: the live custom domain passed HTTPS, security-header
and redirect checks on 5 August 2026.
security.txtretrieval remains an exact correction-release check. - Owner exact-version decision: approved for the controlled successor
transaction; the exact
security.txtbuild and public retrieval checks remain release gates. - Exact owner-approved file SHA-256: none; this is not an approved version.