Security reporting
Help us fix security issues safely.
This is the dedicated reporting channel for suspected vulnerabilities affecting GIBP public systems. Good-faith research conducted within the published policy receives the safe-harbour commitments below.
Before you test
- • Test only GIBP assets owned or operated by The Raeburn Group.
- • Use the minimum access necessary to demonstrate the issue.
- • Stop if you encounter personal, confidential or third-party data.
- • Do not perform denial-of-service, destructive, social-engineering or physical attacks.
- • Do not run high-volume automated scanning that degrades service.
- • Report promptly and give us a reasonable opportunity to investigate before public disclosure.
See the full vulnerability disclosure and safe-harbour policy.
