Approved transparency document for this exact version.

Vulnerability disclosure policy and security contact

Version 0.3 · exact document ACC-DOC-SECURITY

Document: ACC-DOC-SECURITY

Version: 0.3

Exact SHA-256: eb2ae75f54a48c98d93316fd1390d9d205e091f3c1108e509fdacbbaa2571f77

Boundary: Approved transparency document for this exact version.

Vulnerability disclosure

Controlled document: ACC-DOC-SECURITY (decision ACC-SECURITY-001) Candidate version: 0.3
Production scope: fndguide.co.uk and www.fndguide.co.uk. Netlify serves the static site; Fasthosts retains DNS and email. The live custom domain, HTTPS certificate, security headers and www redirect passed their public checks on 5 August 2026.

Reporting a security problem

If you find a security vulnerability in this site, thank you — please tell us privately before telling anyone else.

  • Contact: security@fndguide.co.uk — a dedicated forwarder into the FND Guide mailbox. Mark security reports clearly in the subject line.
  • Secure option: none is offered at this scale; this is stated plainly rather than pretended.
  • Monitored by: the project owner. This is a one-person project: there is no out-of-hours cover, and acknowledgement may take up to 7 days (availability boundary, 17 July 2026).
  • If the route is unavailable: use hello@fndguide.co.uk with “SECURITY” at the start of the subject. If the whole mailbox service is unavailable, the site change log will record a temporary route when the owner can safely provide one.
  • Last external delivery test: 2 August 2026. The security forwarder and direct mailbox received external tests, and the reply path passed SPF, DKIM and DMARC.

Scope

  • In scope: the public website at fndguide.co.uk and the www hostname. It is a static, pre-rendered site with no accounts, no login, no databases and no user-generated content, which keeps the attack surface deliberately small.
  • Out of scope: the hosting provider's own infrastructure (report to them), external sites we link to, and any system not listed here.

What we expect from researchers

Act lawfully and in good faith: do not access, alter or destroy data that is not yours; do not degrade the service for others (no denial-of-service or volumetric testing); do not run social-engineering or phishing attacks against anyone connected to the project; stop and report as soon as you can demonstrate an issue.

In a report, it helps to include: the URL or component, steps to reproduce, what you observed, and how to contact you for follow-up.

What you can expect from us: acknowledgement within the window above, an honest assessment, a fix or documented mitigation as fast as one person can responsibly manage, credit if you want it once resolved (or anonymity if you prefer), and no legal action against good-faith research within this policy. There is no monetary reward programme.

Any personal data in a report is used only to handle the report and is deleted afterwards — see the privacy notice.

security.txt

  • Location: https://fndguide.co.uk/.well-known/security.txt (also reachable through the covered www redirect).
  • Contact: mailto:security@fndguide.co.uk.
  • Policy: https://fndguide.co.uk/security/.
  • Canonical: https://fndguide.co.uk/.well-known/security.txt.
  • Expires: 2027-08-05T00:00:00Z; it must be renewed before that time.
  • Deployment and retrieval test: included in this correction release and must pass on the exact deploy preview and public domain before the release closes.
  • Renewal owner: project owner.

The right route for other problems

  • Something on a page is wrong or unsafe: the corrections route.
  • A complaint about the project: the complaints route.
  • A personal medical or emergency concern: this site cannot help urgently — use NHS 111, or 999 in an emergency.
  • A security vulnerability: this route.

Review record

  • Security owner: project owner / 5 August 2026, controlled successor version 0.3.
  • Data-protection advice: not obtained.
  • Production-host checks: the live custom domain passed HTTPS, security-header and redirect checks on 5 August 2026. security.txt retrieval remains an exact correction-release check.
  • Owner exact-version decision: approved for the controlled successor transaction; the exact security.txt build and public retrieval checks remain release gates.
  • Exact owner-approved file SHA-256: none; this is not an approved version.