GIBP

Security reporting

Help us fix security issues safely.

This is the dedicated reporting channel for suspected vulnerabilities affecting GIBP public systems. Good-faith research conducted within the published policy receives the safe-harbour commitments below.

Before you test

  • • Test only GIBP assets owned or operated by The Raeburn Group.
  • • Use the minimum access necessary to demonstrate the issue.
  • • Stop if you encounter personal, confidential or third-party data.
  • • Do not perform denial-of-service, destructive, social-engineering or physical attacks.
  • • Do not run high-volume automated scanning that degrades service.
  • • Report promptly and give us a reasonable opportunity to investigate before public disclosure.

See the full vulnerability disclosure and safe-harbour policy.

Report a vulnerability

Contact details are optional. Do not include credentials, unnecessary personal data, or data belonging to other people.