Responsible reporting
Report a security issue
Tell us promptly if you suspect a vulnerability, data exposure or unauthorised access involving FieldRadar.
How to report
Email support@fieldradar.co.uk with the subject “CONFIDENTIAL: FieldRadar security report”. The dedicated security mailbox and encrypted intake route remain readiness actions, so avoid putting secrets or live customer records in the first email.
Include
- A clear description and the affected app, site, API or component.
- Reproduction steps using your own test account and non-sensitive data.
- Observed and expected behaviour, approximate time and app/browser version.
- Your preferred contact details for coordination.
Please avoid
- Accessing, changing, downloading or deleting data that is not yours.
- Disrupting service, running denial-of-service or high-volume automated tests.
- Publishing details before we have had a reasonable opportunity to investigate and coordinate.
- Sending passwords, authentication codes, private keys or unnecessary personal/project data.
What to expect
Reports are triaged on a best-effort basis. FieldRadar does not currently operate a bug bounty, guaranteed acknowledgement time or legal safe-harbour programme. We may ask for more detail, provide a safer test route, or coordinate disclosure after remediation.
For ordinary product faults use support. For service availability see status and incident reporting.