Contact
Email arran@cs-code.com with the subject “Security vulnerability”. Initially include the affected URL or component, impact, reproducible steps and a safe proof of concept. Do not send credentials, customer data, classified information or source archives.
Good-faith research
Keep testing proportionate, use accounts and data you control, avoid privacy violations or disruption, and stop if you access data that is not yours. Do not use social engineering, denial of service, physical attacks or third-party systems.
Our response targets
- Acknowledge a credible report within 2 working days.
- Provide an initial assessment within 5 working days.
- Share progress at reasonable intervals.
- Coordinate disclosure after a fix or agreed mitigation is available.
Safe harbour
Where research follows this policy, is conducted in good faith and remains within the law, Arctic Parade Ltd will not initiate legal action solely because of that research. This does not authorise testing of customer deployments or third-party infrastructure.
Recognition
There is currently no guaranteed bug bounty. Public recognition may be offered with the reporter’s consent after remediation.

