Vulnerability Disclosure Policy
Effective 24 June 2026
Reporting a vulnerability
If you discover a security vulnerability in Patch14, please report it by emailing security@graniteandfleur.com. Do not disclose the issue publicly until we have had an opportunity to investigate and respond.
What to include
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue
- Any proof-of-concept code or screenshots (optional but helpful)
- Your contact details if you would like us to credit you
Our commitments
- We will acknowledge your report within 5 business days
- We will keep you informed of our progress
- We will not take legal action against researchers acting in good faith under this policy
- We aim to resolve valid vulnerabilities within 90 days of confirmation
Scope
This policy covers the Patch14 web application at patch14.co.uk. It does not cover third-party services we integrate with (Supabase, Stripe, Resend, Vercel).
Out of scope
- Denial of service attacks
- Social engineering of Patch14 staff or customers
- Physical attacks against our infrastructure
- Vulnerabilities in third-party dependencies not directly exploitable in Patch14
Machine-readable: /.well-known/security.txt