NODE · LON-01|LONDON --:--:--
DC-Services — Digital Claims Services Limited
Legal Documentation

DC-Services UK Vulnerability Disclosure Policy

How to report a suspected security issue safely, and how DC-SERVICES UK responds.

This policy describes the safe and responsible way to report a suspected security vulnerability in any service operated by Digital Claims Services Limited (trading as DC-SERVICES UK), and how reports are handled. It is informational only and is not legal advice.

Last reviewed: February 2026 · 20 sections

vulnerability-disclosure-policy.pdf · A4 · brandedAll documents
01

Purpose of the policy

  1. 1.1DC-SERVICES UK publishes this policy so that security researchers and users have a clear, safe route to report suspected vulnerabilities.
  2. 1.2A vulnerability is a weakness in a system that could be exploited to compromise confidentiality, integrity or availability.
  3. 1.3The policy sets expectations for both the reporter and DC-SERVICES UK.
  4. 1.4Reports submitted in good faith under this policy are welcomed and acknowledged.
02

Responsible disclosure principle

  1. 2.1Reporters must give DC-SERVICES UK a reasonable opportunity to investigate and remediate before any public disclosure.
  2. 2.2Responsible disclosure protects users while a fix is being prepared.
  3. 2.3DC-SERVICES UK undertakes to respond promptly and to coordinate timing with the reporter.
  4. 2.4Co-ordinated disclosure dates are agreed in writing where appropriate.
03

What may be reported

  1. 3.1Suspected vulnerabilities in any internet-facing service operated by DC-SERVICES UK may be reported.
  2. 3.2Reports may concern authentication, access control, data exposure, injection, configuration or third-party components.
  3. 3.3Reports about social engineering or physical security may also be submitted.
  4. 3.4Hypothetical issues without a credible path to impact may be closed as informational.
04

What must not be tested

  1. 4.1Testing must not access, modify, copy or delete data that does not belong to the reporter.
  2. 4.2Testing must not disrupt service for other users, including denial-of-service or load testing.
  3. 4.3Testing must not target systems hosted by third parties on our behalf without their express permission.
  4. 4.4Testing must respect privacy, intellectual property and the law.
05

Prohibited activity

  1. 5.1Social engineering of DC-SERVICES UK staff or clients, physical intrusion, and any form of extortion are prohibited.
  2. 5.2Prohibited activity removes the protections of this policy from the reporter.
  3. 5.3Prohibited activity may be reported to law enforcement.
  4. 5.4Reporters in doubt should ask before acting.
06

Safe reporting channel

  1. 6.1Reports should be sent to security@dc-service.uk and may be encrypted using the public key published on this page or supplied on request.
  2. 6.2Submissions are received by the Security Office and logged confidentially.
  3. 6.3Reporters may remain pseudonymous if they choose.
  4. 6.4Reporters should not file reports through general support channels.
07

Required report details

  1. 7.1A useful report describes the affected system, the vulnerability, reproduction steps and an assessment of potential impact.
  2. 7.2Where possible, the report includes proof-of-concept evidence that does not expose third-party data.
  3. 7.3Screenshots and logs should redact data belonging to other users.
  4. 7.4A means of contact is helpful to allow follow-up questions.
08

Acknowledgement process

  1. 8.1DC-SERVICES UK acknowledges receipt of every in-scope report within five working days.
  2. 8.2Acknowledgement includes an internal reference number for further correspondence.
  3. 8.3Acknowledgement does not yet confirm the existence or severity of the issue.
  4. 8.4Reporters can request a status update at any time using the reference number.
09

Initial triage

  1. 9.1Initial triage validates whether the report describes a real vulnerability in a system within scope.
  2. 9.2Triage is completed within ten working days for most reports.
  3. 9.3Reports out of scope are closed with a written explanation.
  4. 9.4Reports requiring further information are followed up with the reporter.
10

Severity classification

  1. 10.1Validated vulnerabilities are classified by impact and exploitability, using an industry-aligned scoring approach.
  2. 10.2Severity drives the remediation timetable and the communication cadence with the reporter.
  3. 10.3Severity classifications are reviewed if new information changes the picture.
  4. 10.4Reporters are told the severity assigned to their report.
11

Remediation process

  1. 11.1Remediation plans are produced for every validated vulnerability and tracked to closure.
  2. 11.2Critical and high-severity issues are prioritised and may receive emergency change handling.
  3. 11.3Where a full fix is delayed, a documented mitigation is put in place.
  4. 11.4Remediation evidence is retained internally.
12

Communication with reporter

  1. 12.1Reporters are updated at meaningful milestones — triage outcome, severity, planned remediation date and final closure.
  2. 12.2Updates are sent through the channel used to submit the report unless the reporter requests otherwise.
  3. 12.3Reporters can ask for additional context within reason.
  4. 12.4Final closure includes thanks where credit is welcome.
13

Confidentiality of reports

  1. 13.1Reports and reporter details are treated as confidential and shared internally only with people who need to know.
  2. 13.2External disclosure of report content is co-ordinated with the reporter where practicable.
  3. 13.3Confidentiality continues after the report is closed.
  4. 13.4Personal data in reports is processed under our Privacy Policy.
14

No public disclosure without consent

  1. 14.1DC-SERVICES UK will not publicly name a reporter without that reporter's consent.
  2. 14.2Reporters may publish their own write-ups after remediation, subject to embargoed timelines agreed in advance.
  3. 14.3Premature public disclosure may invalidate the protections of this policy.
  4. 14.4Where DC-SERVICES UK publishes an advisory, the reporter is offered the chance to review it first.
15

Protection of client data

  1. 15.1Reporters must not exfiltrate, retain or share data belonging to clients or third parties encountered during testing.
  2. 15.2Where such data is unavoidably encountered, it must be reported, not retained.
  3. 15.3DC-SERVICES UK will work with the reporter to ensure any such data is securely deleted.
  4. 15.4Client data confidentiality takes precedence over disclosure timelines.
16

Out-of-scope systems

  1. 16.1Systems hosted or operated by third parties on our behalf are out of scope unless we have specifically agreed otherwise.
  2. 16.2Marketing or test environments not handling real client data are out of scope by default.
  3. 16.3Reports against out-of-scope systems are closed with guidance to contact the responsible party.
  4. 16.4The in-scope/out-of-scope list is reviewed periodically.
17

Third-party platforms

  1. 17.1Vulnerabilities in third-party platforms used by DC-SERVICES UK should be reported to those vendors using their own disclosure programmes.
  2. 17.2Where impact reaches DC-SERVICES UK clients, the report can additionally be sent to security@dc-service.uk.
  3. 17.3DC-SERVICES UK will coordinate with the vendor where practicable.
  4. 17.4Vendor disclosure timelines are determined by the vendor, not by DC-SERVICES UK.
18

Legal limitations

  1. 18.1Good-faith research conducted within this policy is welcomed; activity outside this policy may breach UK law.
  2. 18.2Nothing in this policy is a waiver of rights or remedies that DC-SERVICES UK or third parties may have at law.
  3. 18.3Where law requires reporting to authorities, DC-SERVICES UK will comply.
  4. 18.4Reporters uncertain about scope should ask before acting.
19

Abuse prevention

  1. 19.1The reporting channel is not a route for extortion, threats or marketing pitches.
  2. 19.2Abusive submissions are blocked and may be reported to authorities.
  3. 19.3Repeat abuse is logged and may be escalated.
  4. 19.4Legitimate researchers are unaffected by anti-abuse controls.
20

Policy review and update

  1. 20.1This policy is reviewed at least annually and whenever scope, contact details or processes change.
  2. 20.2Reviews are owned by the Security Office with sign-off from the Compliance Office.
  3. 20.3Updates are version-controlled and published with a new 'Last reviewed' date.
  4. 20.4Active reporters are told of changes that materially affect open reports.
Frequently Asked Questions

Questions about this page

How do I report a security issue?
Email security@dc-service.uk with a clear description, reproduction steps and an impact assessment. You may encrypt the email using our published key.
Do you pay bug bounties?
DC-SERVICES UK does not currently operate a paid bounty programme. Good-faith reports are acknowledged and credited with the reporter's consent.
Can I publish my findings?
Yes, after we have remediated the issue and agreed a publication date with you. Premature disclosure may invalidate the protections of this policy.
What if I find data belonging to someone else?
Stop, do not retain the data, and report it to us immediately. We will arrange secure deletion and assess any notification obligation.