Report Security Issues


Security Vulnerability Disclosure & Bounty Policy

If you have discovered a security vulnerability affecting stneotsgiftsandtoys.uk, we encourage you to contact us immediately at contact@stneotsgiftsandtoys.uk.

We will review all legitimate vulnerability reports and make reasonable efforts to resolve confirmed security issues as quickly as possible. Before submitting a report, please review the following principles, bounty requirements, reward guidelines and exclusions.

FUNDAMENTAL PRINCIPLES

If you follow the principles below when investigating and reporting a security issue to St Neots Gifts & Toys, we will not initiate legal action or request a law-enforcement investigation against you solely because of your good-faith security research.

We ask that:

  1. You give us a reasonable amount of time to investigate and resolve the reported vulnerability before publicly disclosing it or sharing information with others.
  2. You do not access, modify or interact with another person’s private account or personal data without the account owner’s permission.
  3. You make a good-faith effort to avoid privacy violations, data destruction, service interruption or degradation of our website and services.
  4. You do not exploit a discovered vulnerability for personal gain or any purpose beyond what is reasonably necessary to demonstrate the issue.
  5. You do not attempt to access sensitive company information, customer information or additional systems beyond what is required to confirm the vulnerability.
  6. You comply with all applicable laws and regulations.

BOUNTY PROGRAM

We recognise and may reward security researchers who help us protect our customers and services by responsibly reporting vulnerabilities.

Any monetary reward is offered entirely at the discretion of St Neots Gifts & Toys and will be based on the vulnerability’s severity, impact, exploitability, report quality and other relevant factors.

To be considered for a bounty, you must:

  1. Follow the fundamental principles listed above.
  2. Report a genuine security vulnerability affecting our website, systems, services or infrastructure that creates a meaningful security or privacy risk.
  3. Submit your report directly to contact@stneotsgiftsandtoys.uk. Please do not contact individual employees.
  4. Include complete and reproducible instructions, evidence and technical details that allow us to verify the issue.
  5. Immediately disclose in your report if you accidentally accessed personal data, account information, confidential information or internal configurations during your investigation.
  6. Avoid downloading, copying, modifying, deleting or retaining customer or company data.
  7. Allow us reasonable time to investigate and resolve the issue before publishing any details.

We investigate and respond to valid reports. Response times may vary depending on the number, complexity and severity of reports received.

We reserve the right to publish information about resolved vulnerabilities and submitted reports where appropriate.

REWARD GUIDELINES

Rewards are based on the security impact of a confirmed vulnerability. All reward decisions and amounts are at our sole discretion.

Please note:

  1. Reports must include clear descriptions and reproducible steps. Reports that cannot be reproduced may not qualify for a reward.
  2. If duplicate reports are submitted, the reward will generally be given to the first report that we can fully reproduce.
  3. Multiple vulnerabilities resulting from the same underlying issue may be treated as one vulnerability and awarded one bounty.
  4. Rewards are determined based on factors including severity, impact, ease of exploitation and report quality.
  5. The amounts listed below are the maximum rewards normally available for each severity level.

Critical-Severity Vulnerabilities — Up to £200

Vulnerabilities that may allow full system compromise, administrative access, remote code execution, significant financial theft or complete account takeover.

Examples include:

  • Remote code execution
  • Remote shell or command execution
  • Vertical authentication or authorisation bypass
  • SQL injection exposing sensitive or targeted data
  • Full administrative account access
  • Large-scale customer account takeover

High-Severity Vulnerabilities — Up to £100

Vulnerabilities that significantly affect the security of the website, customer accounts or business systems.

Examples include:

  • Horizontal or lateral authentication bypass
  • Disclosure of sensitive company or customer information
  • Stored cross-site scripting affecting another user
  • Local file inclusion
  • Insecure handling of authentication cookies
  • Significant privilege escalation

Medium-Severity Vulnerabilities — Up to £50

Vulnerabilities that may affect multiple users and require little or no user interaction.

Examples include:

  • Significant business-logic flaws
  • Insecure direct object references
  • Authorisation-control weaknesses
  • Security issues affecting multiple customer accounts

Low-Severity Vulnerabilities

Issues that affect individual users and require significant interaction, special conditions or prerequisites to exploit may not receive a monetary reward.

Examples include:

  • Open redirects
  • Reflected cross-site scripting
  • Low-sensitivity information disclosure
  • Issues requiring a successful man-in-the-middle attack

ISSUES THAT SHOULD NOT BE REPORTED

The following issues will generally not qualify for a reward:

  • Vulnerabilities found only through automated scanning without demonstrated impact
  • Missing security headers without a practical exploit
  • Clickjacking on pages without sensitive actions
  • Self-XSS
  • Social-engineering or phishing attempts
  • Denial-of-service or resource-exhaustion testing
  • Spam-related issues
  • Reports based only on outdated software versions without a working exploit
  • Physical-security attacks
  • Attacks requiring access to a victim’s device or email account
  • Previously reported or already known vulnerabilities
  • Issues affecting third-party services that we do not control

CONTACT US

Security reports should be sent to:

St Neots Gifts & Toys
Website: stneotsgiftsandtoys.uk
Email: contact@stneotsgiftsandtoys.uk
Telephone: +44 73 0736 8259
Address: 38 Huntingdon St, St. Neots PE19 1BB, United Kingdom