Security Policy
Responsible Disclosure
We take the security of QuickEasyTax and its users seriously. If you have discovered a potential security vulnerability or weakness in our systems, we encourage you to report it responsibly so we can address it promptly. We are committed to working with security researchers in good faith.
How to report
Send your report to security@quickeasytax.co.uk or use the form below.
- We will acknowledge your report within 24 hours.
- We will provide a full response and remediation plan within 72 hours.
Please include: a description of the vulnerability, steps to reproduce, the potential impact, and any proof-of-concept code or screenshots.
What we ask of you
- Act in good faith — do not exploit any vulnerability beyond what is necessary to demonstrate its existence.
- Do not access, modify, or delete data belonging to other users.
- Do not perform denial-of-service attacks or spam our systems.
- Keep details of any vulnerability confidential until we have resolved it.
- Do not disclose the vulnerability publicly before we have had a reasonable opportunity to fix it.
What we commit to
- We will not take legal action against researchers who report vulnerabilities responsibly and act in good faith.
- We will acknowledge and credit researchers in our acknowledgments section (if desired).
- We will keep you informed of our progress in addressing your report.
- We will treat your personal information with respect and in accordance with our privacy policy.
Data breach notification
In the event of a confirmed data breach, we are committed to notifying the HMRC Developer Hub and the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, in accordance with UK GDPR obligations. We will also notify affected customers without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
Acknowledgments
(None to date)