Cyber Resilience

Elmdene welcomes reports from customers, researchers, partners, and other stakeholders who identify potential security or privacy vulnerabilities in Elmdene products, software, services, or websites.

If you believe you have identified a vulnerability, please report it by email.

Report a Vulnerability

Send your report, including as much detail as possible, to our dedicated inbox.

Email CRA@elmdene.co.uk

To help us investigate and respond effectively, please provide:

  • Your name and contact email address.
  • The affected product, software version, service, or webpage.
  • A detailed description of the vulnerability.
  • Steps required to reproduce the issue.
  • The potential impact of the vulnerability.
  • Screenshots, log files, network captures, or other supporting evidence.
  • Proof-of-concept (PoC) information where applicable.

Upon receipt of your report, Elmdene will:

  1. Acknowledge receipt of your submission.
  2. Review and assess the reported vulnerability.
  3. Contact you if additional information is required.
  4. Work to validate and remediate confirmed vulnerabilities.
  5. Provide updates on the status of the investigation where appropriate.

Our aim is to acknowledge vulnerability reports within 72 hours of receipt.

Elmdene will treat all vulnerability reports confidentially and use the information solely for the purpose of investigating and resolving the reported issue.

Personal information provided as part of the reporting process will be handled in accordance with applicable data protection legislation and Elmdene's Privacy Policy.

We ask all reporters to follow responsible vulnerability disclosure practices and not undertake any activity that could negatively affect Elmdene, its customers, or third parties.

Specifically, please:

  • Do not exploit any vulnerability beyond what is necessary to demonstrate its existence.
  • Do not access, modify, or delete data belonging to others.
  • Do not publicly disclose vulnerability details before Elmdene has had a reasonable opportunity to investigate and remediate the issue.
  • Do not conduct denial-of-service attacks or other activities that may impact service availability.
  • Do not use social engineering, physical intrusion, or other unlawful methods to identify vulnerabilities.

Elmdene appreciates the efforts of security researchers and customers who help us maintain the security of our products and services through responsible disclosure.