PLUMPED LTD welcomes reports of security vulnerabilities. Plumped handles facial images and skin health information, so security matters to us more than it might to an ordinary app.
If you have found a problem, please tell us. This page explains how, and what we promise in return.
1. How to report
Email: contact@plumped.co.uk with "Security" in the subject line.
Please include:
- a description of the issue and why you think it is a problem;
- the steps needed to reproduce it;
- the URL, endpoint, app version or screen affected;
- any proof of concept, screenshots or logs;
- how you would like to be credited, or whether you would prefer to stay anonymous.
Report in English if you can.
2. What we promise
| Stage | Timing |
|---|---|
| We acknowledge your report | Within 3 working days |
| We give you an initial assessment | Within 10 working days |
| We keep you updated | At least every 14 days until it is resolved |
| We tell you when it is fixed | As soon as the fix is deployed |
We will not take legal action against you, and we will not ask anyone else to, provided you follow this policy in good faith.
We will credit you publicly if you want, once the issue is fixed.
3. What we ask of you
- Give us a reasonable time to fix the issue before you tell anyone else. We suggest 90 days, and we are happy to discuss it.
- Only test against your own account and your own data.
- Do not access, modify, download or delete anyone else's data. If you accidentally see someone else's data, stop, do not save a copy, and tell us immediately.
- Do not run denial of service tests, volumetric attacks, or anything that degrades the Service for other users.
- Do not use social engineering, phishing or physical attacks against our staff, our users or our suppliers.
- Do not use automated scanners that generate high volumes of traffic.
- Do not demand payment in exchange for disclosure. We do not pay for reports, and a demand for payment before disclosure will be treated as extortion rather than research.
- Comply with the law, including the Computer Misuse Act 1990 and the data protection law that applies to you.
4. In scope
- plumped.co.uk and its subdomains
- The Plumped iOS application
- The Plumped Android application
- Our public API endpoints
5. Out of scope
Reports about the following will usually be closed without action:
- findings from automated scanners with no demonstrated impact;
- missing security headers with no demonstrated exploit;
- missing best practice configuration such as SPF, DKIM or DMARC on non-mailing domains, unless you can show an exploit;
- rate limiting on non-authentication endpoints;
- self-cross-site scripting requiring the victim to paste code into their own console;
- vulnerabilities in third-party services we use, which should be reported to that provider;
- clickjacking on pages with no sensitive action;
- issues affecting only unsupported or heavily outdated browsers or operating systems;
- social engineering, phishing and physical security;
- denial of service.
6. No bug bounty
We do not currently run a paid bug bounty programme. We recognise researchers publicly with their permission, and we respond promptly and seriously to every report.
7. Your data
If you send us a report, we will process your email address and the contents of your report in order to investigate and respond, on the basis of our legitimate interest in the security of the Service. We keep security reports for 3 years. See the Privacy Policy.
8. Not a security issue?
For general bugs, account problems and support, use contact@plumped.co.uk without the "Security" tag.
For questions about how we handle personal data, use operations@plumped.co.uk.
9. Contact
PLUMPED LTD, 124 City Road, London, England, EC1V 2NX. Company number 16204649.