Legal & Compliance

Vulnerability Disclosure Policy

Published: 24 July 2026 ·  Reviewed annually  ·  Applies to: 3T Restoration Ltd

3T Restoration Ltd welcomes responsible disclosure of security vulnerabilities affecting our website, systems or digital services. This Vulnerability Disclosure Policy (VDP) explains how to report a security concern to us, what you can expect from us in response, and the boundaries within which security research may be conducted. We are committed to working collaboratively with researchers and members of the public to identify and resolve security issues promptly and transparently.

1. Purpose and Scope

This policy applies to security vulnerabilities identified in any digital asset owned or operated by 3T Restoration Ltd, including our primary website at www.3trestoration.co.uk, any associated subdomains, web applications, APIs and publicly accessible digital services. It does not apply to third-party platforms, social media accounts, or services operated by our suppliers or partners — vulnerabilities in those systems should be reported directly to the relevant organisation. This policy is intended to encourage responsible, good-faith security research and to provide a clear, safe channel through which concerns can be raised without fear of legal action, provided the researcher acts within the guidelines set out below.

2. How to Report a Vulnerability

If you believe you have identified a security vulnerability affecting any of our systems, please report it to us as soon as possible by emailing [email protected] with the subject line 'Vulnerability Disclosure'. Your report should include: a clear description of the vulnerability and the potential impact; the affected URL, system or component; step-by-step instructions to reproduce the issue; any supporting evidence such as screenshots, HTTP request/response logs or proof-of-concept code; and your contact details if you are willing to be contacted for follow-up. Please provide as much detail as possible to help us understand and reproduce the issue quickly. You do not need to be a security professional to submit a report — we welcome disclosures from anyone who identifies a genuine concern.

3. What We Ask of Researchers

In order to protect our customers, our systems and the integrity of any investigation, we ask that all security research is conducted responsibly and in accordance with the following guidelines. You must not access, modify, delete or exfiltrate data belonging to 3T Restoration Ltd or any of our customers. You must not disrupt, degrade or deny access to our services, including through denial-of-service attacks, automated scanning at a rate that impacts availability, or any other technique that could cause harm. You must not exploit a vulnerability beyond what is strictly necessary to demonstrate its existence. You must not disclose the vulnerability publicly or to any third party before we have had a reasonable opportunity to investigate and remediate it. You must not conduct social engineering, phishing or physical security testing against our staff, premises or infrastructure. Compliance with these guidelines is a condition of our commitment not to pursue legal action against good-faith researchers.

4. Our Commitments to You

When you submit a vulnerability report in good faith and in accordance with this policy, 3T Restoration Ltd commits to the following. We will acknowledge receipt of your report within five business days. We will investigate your report promptly and keep you informed of our progress where it is appropriate and safe to do so. We will not pursue civil or criminal legal action against you in connection with your research, provided you have acted in good faith and complied with the guidelines in this policy. We will treat your personal information in accordance with our Privacy Policy and will not share your details with third parties without your consent, except where required by law. We will credit you for your discovery if you wish to be acknowledged, once the vulnerability has been resolved and any public disclosure is made.

5. Vulnerability Severity and Prioritisation

We assess reported vulnerabilities using a risk-based approach, taking into account the potential impact on the confidentiality, integrity and availability of our systems and data, and the likelihood of exploitation. Critical and high-severity vulnerabilities — such as those enabling unauthorised access to customer data, remote code execution, authentication bypass or significant data exposure — will be prioritised for immediate investigation and remediation. Medium and low-severity issues will be addressed in order of risk. We aim to remediate critical vulnerabilities within 30 days of confirmation, and all other confirmed vulnerabilities within 90 days, though timelines may vary depending on the complexity of the fix required. We will notify you when a vulnerability you reported has been resolved.

6. Out-of-Scope Vulnerabilities

The following categories of issue are considered out of scope for this policy and will not be investigated as security vulnerabilities: missing security headers that do not present a demonstrable risk; clickjacking on pages that do not contain sensitive actions or authenticated functionality; self-XSS or issues that require the victim to take highly unlikely actions; rate limiting on non-sensitive endpoints; theoretical vulnerabilities with no practical exploit path; issues in third-party software or services that are not under our direct control; reports generated solely by automated scanning tools without manual verification; and social engineering or physical security concerns not related to our digital systems. We ask that you do not submit reports for these categories, as they will not be actioned.

7. Coordinated Disclosure

We support the principle of coordinated vulnerability disclosure. We ask that you allow us a reasonable period — typically 90 days from the date of our acknowledgement — to investigate and remediate a confirmed vulnerability before making any public disclosure. If you believe that a vulnerability poses an immediate and serious risk to users and requires urgent public disclosure before the 90-day period has elapsed, please contact us immediately so that we can work with you to agree an appropriate timeline. We will not request indefinite embargo periods and will work constructively with researchers to agree a disclosure timeline that balances the need for remediation with the public interest in transparency.

8. Bug Bounty

3T Restoration Ltd does not currently operate a paid bug bounty programme. We are unable to offer financial rewards for vulnerability disclosures at this time. However, we are genuinely grateful to researchers who take the time to report security concerns responsibly, and we will acknowledge your contribution publicly — with your permission — once a vulnerability has been resolved. We reserve the right to introduce a formal bug bounty programme in the future, and this policy will be updated accordingly if we do so.

9. Legal Safe Harbour

3T Restoration Ltd will not pursue legal action against individuals who identify and report security vulnerabilities in good faith, provided they comply with the guidelines set out in this policy. We consider good-faith security research to be a valuable contribution to the security of our systems and the protection of our customers. This safe harbour applies to activities conducted strictly within the scope of this policy. It does not apply to activities that cause harm to our systems or data, that involve accessing data beyond what is necessary to demonstrate a vulnerability, or that are conducted with malicious intent. Nothing in this policy limits our right to take action in response to conduct that falls outside these boundaries or that constitutes a criminal offence under the Computer Misuse Act 1990 or any other applicable legislation.

10. Data Protection and Confidentiality

Any personal data you provide when submitting a vulnerability report — including your name, email address and contact details — will be processed by 3T Restoration Ltd solely for the purpose of investigating and responding to your report. We will retain this information only for as long as is necessary for that purpose, in accordance with our data retention schedule. Your information will not be shared with third parties without your consent, except where we are required to do so by law or where disclosure is necessary to protect the safety of our users. All vulnerability reports and associated correspondence are treated as confidential. We will not disclose the details of a reported vulnerability to third parties without your agreement, except where required by law or where necessary to engage specialist technical assistance in resolving the issue.

11. Relationship with Other Policies

This Vulnerability Disclosure Policy should be read alongside our Information Security Overview, Privacy Policy, Cookies Policy and Ethical Code of Conduct. Together, these documents set out our comprehensive approach to information security, data protection and responsible business conduct. Where there is any conflict between this policy and another document, this policy takes precedence in matters relating to vulnerability disclosure. This policy does not create any contractual relationship between 3T Restoration Ltd and any researcher or third party. It represents our current good-faith commitment to responsible disclosure and may be updated at any time.

12. Policy Review and Updates

This Vulnerability Disclosure Policy is reviewed at least annually and updated as necessary to reflect changes in our systems, our security posture, applicable legislation or industry best practice. The current version of this policy is always available on our website. We will not apply changes to this policy retrospectively to reports that were submitted under a previous version. If you have any questions about this policy or wish to discuss a potential disclosure before submitting a formal report, please contact us at [email protected]. We welcome feedback on this policy and are committed to improving our approach to vulnerability disclosure over time.

Report a Vulnerability

To report a security vulnerability, email us with the subject line 'Vulnerability Disclosure'. Include a description of the issue, the affected URL or system, steps to reproduce, and any supporting evidence.

Submit a Disclosure Report

Useful Contacts & Resources

Related Policies

This policy was approved by the directors of 3T Restoration Ltd and published on 24 July 2026. It will be reviewed and updated annually or following any material change in our systems, security posture or applicable legislation. For any queries, contact us at [email protected] or visit our contact page.