How to report
Use the SupportCheck contact route and clearly mark the message as a security report. Include the affected page, what happened and safe reproduction steps. Do not include real resident information, passwords, API keys or copied private records.
What we ask researchers to avoid
- Accessing, changing or deleting another person’s information
- Disrupting the service or running denial-of-service tests
- Automated bulk extraction or high-volume scanning
- Social engineering staff, councils or service users
- Publishing an unresolved issue before we have had reasonable time to investigate
Our response
We will acknowledge a valid report, assess its severity, preserve an audit record and provide progress updates where contact details are supplied. This page is a disclosure channel, not permission to access data or exceed the law.
Security controls
SupportCheck uses organisation-scoped access controls, least-privilege database functions, audit logging, automated tests and monitored official-source workflows. Independent security testing remains a required pilot gate.
Last updated: 9 September 2026