Vulnerability Disclosure Policy

Effective 24 June 2026

Reporting a vulnerability

If you discover a security vulnerability in Patch14, please report it by emailing security@graniteandfleur.com. Do not disclose the issue publicly until we have had an opportunity to investigate and respond.

What to include

Our commitments

Scope

This policy covers the Patch14 web application at patch14.co.uk. It does not cover third-party services we integrate with (Supabase, Stripe, Resend, Vercel).

Out of scope

Machine-readable: /.well-known/security.txt