Where to send reports
Email security@btlocum.com with:
- A clear description of the issue and impact
- Steps to reproduce (cURL or HTTP request preferred)
- The endpoint, page URL, or system component affected
- Your name and how you would like to be credited (or "anonymous")
PGP key available at /security/pgp.asc for sensitive submissions.
What we commit to
- Acknowledgement within 24 hours. A person responds, not an autoresponder.
- Triage within 5 business days. We confirm whether we can reproduce, classify severity, and tell you our remediation plan.
- No legal action against researchers acting in good faith under this policy. We will not contact your employer, file complaints, or pursue criminal proceedings.
- Credit on our security thanks page once the fix ships, unless you ask otherwise.
- Coordinated disclosure. We work with you on a public disclosure timeline, typically 90 days from confirmed receipt.
What we ask of you
- Do not access, modify, or delete data belonging to other users. Use test accounts only.
- Do not exfiltrate, store, or share user data discovered through your research.
- Do not run automated scans against production at high rates without notifying us first.
- Do not perform denial-of-service attacks or social engineering.
- Wait until we have shipped a fix before publicly disclosing.
Scope
In scope:
- app.locumplatform.com
- api.locumplatform.com
- locumplatform.com (marketing site)
- Locum mobile apps (iOS, Android) — when launched
Out of scope:
- Third-party services (PayFast, our hosting provider, SendGrid) — please report directly to them
- Findings dependent on outdated browser versions or missing security headers without demonstrated impact
- Self-XSS, clickjacking on pages without authenticated state changes
- Social engineering of staff or users
Rewards
We do not yet run a paid bug bounty. Researchers receive public credit (with consent) and our enthusiastic thanks. We plan to launch a formal bounty programme in Q4 2026; sign up at security@btlocum.com to be notified.