Security

We take security seriously and welcome responsible disclosure.

Reporting a vulnerability

Please include:

  • A clear description and impact
  • Steps to reproduce (and any proof-of-concept, if safe)
  • Affected URLs and screenshots (if relevant)

Please do not:

  • Run denial-of-service tests
  • Attempt to access data that is not yours
  • Social-engineer our staff or suppliers

What you can expect

  • We aim to acknowledge reports within 2 business days
  • We will keep you updated on progress and remediation

Email authenticity (anti-impersonation)

We publish SPF, DKIM and DMARC records for our domain. If you receive an email claiming to be from us, verify that the sender domain is exactly @salestoaccounts.co.uk.