Security Reporting Policy
This policy gives security researchers and users a clear route for reporting suspected vulnerabilities affecting Passport-Photo.co.uk.
How to report a security issue
Email support@passport-photo.co.uk with the subject line "Security report". Please send a concise description of the suspected issue and enough safe evidence for it to be reviewed.
- Identify the affected public URL or service area.
- Describe the steps needed to reproduce the issue without including passwords, payment details, passport images or unnecessary personal data.
- Explain the likely impact and whether the issue is repeatable.
- Include a safe proof of concept only when it does not expose another person, damage data or interrupt the service.
- Provide a contact address for follow-up questions.
Systems covered by this policy
This reporting route covers security issues in the public Passport-Photo.co.uk website and services operated for this domain.
Third-party platforms and official government services are outside this policy. Report an issue affecting a third-party provider directly to that provider whenever possible.
- In scope: public pages, service workflows and first-party endpoints operated for Passport-Photo.co.uk.
- Out of scope: GOV.UK, HM Passport Office and other government systems.
- Out of scope: independent third-party services such as payment, hosting, email or analytics platforms when the issue exists only in that provider.
- Customer support questions and dissatisfaction with an official application decision are not security vulnerabilities.
Safe testing boundaries
This policy does not authorise unlawful access or testing that harms users or the service. Stop testing and report the issue if personal data, private files or another person’s account becomes visible.
- Do not access, change, download or delete another person’s data.
- Do not upload malware, send spam, attempt denial of service or run high-volume automated scans.
- Do not test payment cards, credentials or accounts that you do not own or have explicit permission to use.
- Do not use social engineering, phishing, physical intrusion or attacks against staff or suppliers.
- Do not publicly disclose exploitable details before the report has been reviewed and a responsible disclosure path has been discussed.
What happens after a report
Reports are reviewed to determine whether the issue can be reproduced, whether it affects a first-party service, and what remediation is appropriate.
A response or request for more information will be sent when practical. Complex issues may require investigation with an infrastructure or service provider, so this page does not promise a fixed resolution time.
A security report does not create a reward, employment, confidentiality or compensation agreement unless a separate written agreement is made.
Privacy and sensitive evidence
Send only the minimum information needed to explain the issue. Redact passport images, order details, payment information, access tokens and personal data wherever possible.
Contact details and technical evidence may be retained as needed to investigate, remediate and document the report. For general data-rights or deletion questions, use the Privacy Policy and Contact page.