1. Purpose
This policy sets out how Murzo Group, company number 17327540, handles good-faith reports of security vulnerabilities affecting Murzo Group websites, systems, platforms, services, and digital assets. References to Murzo Group include Murzo Group and its relevant group companies unless the context requires otherwise.
The purpose of this policy is to provide a clear reporting route, encourage responsible and coordinated disclosure, reduce risk to users and systems, and define safe boundaries for security research.
2. Scope
This policy applies to vulnerabilities affecting systems, websites, applications, APIs, infrastructure, or digital services owned, operated, or controlled by Murzo Group.
Third-party platforms, suppliers, hosting providers, payment providers, social media services, plugins, analytics services, and embedded services are outside Murzo Group's direct control unless Murzo Group has expressly accepted responsibility for the affected asset.
If a vulnerability appears to affect a third-party service, reporters should notify that third party directly where appropriate and may also inform Murzo Group if Murzo Group users or data may be affected.
3. How to Report a Vulnerability
Security reports should be sent to admin@murzo.co.uk with the subject line "Security Vulnerability Disclosure".
Reports should include, where possible:
- The affected domain, URL, endpoint, system, product, or asset
- A clear description of the vulnerability and potential impact
- Steps to reproduce the issue safely
- Any proof-of-concept details, screenshots, logs, timestamps, or request examples necessary to validate the report
- The reporter's contact details and any requested acknowledgement preference
- Whether the vulnerability may already have been publicly disclosed or exploited
Reporters must not include personal data, secrets, credentials, payment data, or confidential information unless strictly necessary to explain the issue.
4. Good-Faith Testing Rules
Murzo Group welcomes good-faith, low-impact vulnerability research that is lawful, proportionate, and designed to avoid harm.
Researchers must:
- Use the minimum testing necessary to confirm a vulnerability
- Avoid privacy violations, data exfiltration, data modification, service disruption, persistence, or destructive activity
- Stop testing immediately if sensitive data, unauthorised access, instability, or unintended impact is encountered
- Report the issue promptly and keep details confidential until Murzo Group has had a reasonable opportunity to investigate and remediate
- Comply with applicable law and avoid activity that would reasonably be considered malicious, coercive, or reckless
5. Prohibited Activity
The following activities are not authorised by this policy:
- Denial-of-service, load, stress, resource exhaustion, or availability testing
- Social engineering, phishing, spam, fraud, impersonation, or harassment
- Physical attacks, facility access attempts, device theft, or tampering
- Malware, ransomware, backdoors, persistence, credential theft, or lateral movement
- Accessing, copying, deleting, altering, disclosing, or retaining data that does not belong to the reporter
- Testing against third-party systems without permission from the relevant owner
- Extortion, threats, public pressure, sale of vulnerability details, or demands for payment
6. Safe Harbour Position
Murzo Group does not intend to pursue legal action against researchers who act in good faith, comply with this policy, avoid harm, and report vulnerabilities responsibly.
This safe harbour does not apply to unlawful, harmful, reckless, coercive, destructive, fraudulent, privacy-invasive, or out-of-scope activity. It also does not bind third parties, law enforcement, regulators, suppliers, service providers, or other affected organisations.
7. Murzo Group Response Process
Murzo Group will aim to handle vulnerability reports in a structured and proportionate way.
- Acknowledge receipt where practical
- Triage the report and determine whether it is in scope
- Assess severity, exploitability, affected assets, data risk, and business impact
- Prioritise remediation or mitigation based on risk
- Coordinate follow-up questions with the reporter where needed
- Notify affected parties, regulators, suppliers, or users where legally or operationally required
Murzo Group does not guarantee a fixed remediation timeframe, public acknowledgement, bounty, compensation, or ongoing correspondence for every report.
8. Public Disclosure
Reporters must not publicly disclose vulnerability details until Murzo Group has completed investigation and remediation, or until Murzo Group has agreed disclosure timing in writing.
Murzo Group may decline, delay, or restrict public disclosure where disclosure could increase risk to users, systems, third parties, or active remediation work.
Where public disclosure is agreed, Murzo Group may request that technical detail is limited to reduce exploitation risk.
9. Rewards & Acknowledgements
Murzo Group does not operate a bug bounty programme unless expressly stated in writing. Submission of a vulnerability report does not create any entitlement to payment, reward, employment, contract, or public credit.
Murzo Group may, at its sole discretion, acknowledge researchers who provide helpful, lawful, and good-faith reports.
10. Data Protection & Confidentiality
Reporters must avoid accessing personal data or confidential information. If such information is accidentally encountered, testing must stop and the exposure must be reported immediately without copying, sharing, retaining, or using the information.
Murzo Group will handle vulnerability reports in line with its Data Protection Policy, Information Classification & Handling Policy, Cybersecurity & Data Breach Policy, and applicable legal obligations.
11. Security.txt
Murzo Group may publish a machine-readable security contact file, commonly known as security.txt, to help security researchers find current reporting information.
Where used, security.txt should support this policy and may include contact, policy, preferred language, expiry, and canonical URL information.
12. Review
This policy may be reviewed and updated periodically to reflect changes in Murzo Group systems, threat conditions, legal requirements, standards, reporting channels, or security operations.