Security Vulnerability Disclosure Policy
Last Updated: 29 July 2026
At IT Desk, we take the security of our systems, services and customer information seriously. We appreciate the efforts of security researchers and members of the security community who help us identify potential vulnerabilities responsibly.
This policy explains how to report a suspected security vulnerability and what you can expect from us in return.
Reporting a Vulnerability
If you believe you have discovered a security vulnerability affecting IT Desk's website, systems or online services, please let us know as soon as possible.
Please email:
When reporting a vulnerability, please include as much information as possible, including:
A description of the issue.
The affected page, system or service.
Steps to reproduce the issue.
Screenshots where appropriate.
Any supporting technical information that may help us investigate.
The more detail you can provide, the quicker we can assess the issue.
What We Ask of Security Researchers
To help protect our customers and systems, we ask that you:
Act in good faith.
Give us reasonable time to investigate and resolve the issue before publicly disclosing it.
Avoid accessing, modifying or deleting data that does not belong to you.
Avoid disrupting our services or those of our customers.
Do not attempt denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks.
Do not use social engineering, phishing or physical attacks against IT Desk employees or customers.
Only perform testing that is necessary to demonstrate the vulnerability.
Our Commitment
If you report a genuine security vulnerability responsibly, we will:
Acknowledge receipt of your report as soon as reasonably possible.
Investigate the issue.
Keep you informed of the progress where appropriate.
Work to resolve confirmed vulnerabilities in a reasonable timeframe.
Treat you professionally and respectfully throughout the process.
Where your research has been carried out responsibly and in accordance with this policy, we will not pursue legal action solely as a result of your security research.
Scope
This policy applies to:
Other publicly accessible IT Desk web services and applications.
It does not authorise testing against customer environments, customer systems or third-party services managed by IT Desk unless you have explicit written permission from the owner of those systems.
Out of Scope
The following activities are outside the scope of this policy:
Spam or phishing reports.
Social engineering attacks.
Physical security testing.
Denial-of-Service (DoS) or Distributed Denial-of-Service (DDoS) attacks.
Automated scanning that significantly impacts service availability.
Vulnerabilities requiring unrealistic attack scenarios.
Reports relating solely to missing security headers, outdated software versions or best-practice recommendations without a demonstrable security impact.
Disclosure
We ask that you do not publicly disclose any vulnerability until we have had a reasonable opportunity to investigate and remediate the issue.
Responsible disclosure helps protect our customers and users while allowing us to address security concerns effectively.
No Bug Bounty Programme
IT Desk does not currently operate a bug bounty or financial reward programme.
We sincerely appreciate responsible vulnerability reports and the time taken by security researchers to help improve our security.
Contact
If you wish to report a security vulnerability or have any questions regarding this policy, please contact:
IT Desk
IT Desk House
2–6 Barnsley Road
Rotherham
S63 9NF
Email: saint@itdeskuk.com
Telephone: 01709 470 073
