Security

Responsible Disclosure

How to report a potential security vulnerability safely.

Effective: 18 July 2026 Last reviewed: 18 July 2026 Version: 1.0

1. Reporting

Email info@eatwelltechsolutions.co.uk with the subject “ClassControl security report”. Include affected URLs, reproduction steps, impact and supporting evidence.

2. Safe-harbour expectations

  • Do not access, alter or retain data belonging to others.
  • Do not disrupt service, use denial-of-service techniques or automated high-volume scanning.
  • Do not publicly disclose before a reasonable remediation period.
  • Stop testing and report immediately if sensitive data is encountered.

3. Our response

We aim to acknowledge legitimate reports, investigate them and communicate material progress. Response time depends on severity and report quality. This policy does not create a bug-bounty entitlement.