Services

Products

Company

Resources

EN
EN
EN
EN

Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Last updated: 16 August 2026


Spicy Mango takes the security of its systems, products and services seriously. We welcome responsible reports from security researchers and others who believe they have identified a security vulnerability in a Spicy Mango-operated service.


This policy explains how to report a vulnerability, the types of security research we consider acceptable, and what you can expect from us when you make a report.


Contact

Please report security vulnerabilities to:

security@spicymango.co.uk


If you believe the vulnerability presents an immediate and significant risk to customers, users or production services, state Critical security vulnerability in the subject line.


Please do not send vulnerability details to individual employees, public support channels or social media accounts.


Scope

This policy applies to publicly accessible systems, services and applications operated by Spicy Mango where the relevant domain or service publishes a security.txt file that references this policy.


This may include:


  • Spicy Mango corporate websites and public web applications;

  • public APIs and internet-facing services operated by Spicy Mango;

  • Spicy Mango-operated Gameday services;

  • Spicy Mango-operated AuthIDConnect services; and

  • other Spicy Mango-operated domains or services whose security.txt file points to this policy.


security.txt file applies to the hostname from which it is served. The presence of this policy on one Spicy Mango domain does not automatically bring every Spicy Mango, customer or third-party system into scope.


Customer-controlled environments, customer infrastructure, third-party services and systems operated by another organisation are outside the scope of this policy unless their own security.txt file or published security documentation explicitly states otherwise.


If you are unsure whether a system is in scope, contact us before carrying out further testing.


What to include in a report


Please provide enough information for us to understand, reproduce and assess the issue. Where possible, include:


  • the affected hostname, URL, API endpoint, application or service;

  • a clear description of the vulnerability and its potential impact;

  • the steps required to reproduce the issue;

  • any relevant request and response examples;

  • screenshots, logs or proof-of-concept material where useful;

  • the date and time the issue was observed;

  • whether you believe the vulnerability has been exploited or is being actively exploited; and

  • your preferred contact details for follow-up.


Please remove or redact credentials, access tokens, personal data and other sensitive information unless it is essential to demonstrate the vulnerability.


Responsible security research


We support good-faith security research carried out carefully and proportionately.

When investigating a potential vulnerability:


  • make a reasonable effort to avoid privacy violations, degradation of service, disruption to production systems and damage to data;

  • use the minimum level of access and interaction required to demonstrate the issue;

  • stop testing and report the issue if you gain unintended access to personal data, confidential information, credentials, secrets or another user's account;

  • do not retain, download, copy or exfiltrate more data than is necessary to demonstrate the vulnerability;

  • keep information obtained during your research secure;

  • use accounts and data that you own or are authorised to use wherever possible; and

  • report the vulnerability to us promptly after confirming it.


Activities outside this policy


This policy does not authorise:


  • denial-of-service or distributed denial-of-service testing;

  • high-volume, destructive, invasive or availability-impacting automated scanning;

  • deliberate degradation, interruption or exhaustion of a service or its resources;

  • modification, deletion, corruption or destruction of data;

  • accessing, downloading or retaining unnecessary personal, customer or confidential data;

  • accessing another user's account beyond the minimum necessary to demonstrate an access-control issue;

  • credential stuffing, password spraying or large-scale brute-force testing;

  • phishing, social engineering or impersonation of Spicy Mango employees, customers, suppliers or users;

  • physical attacks against offices, staff, infrastructure or data centres;

  • malware deployment, persistence, ransomware or destructive payloads;

  • attacks against third-party suppliers, customers or infrastructure that Spicy Mango does not operate;

  • testing intended primarily to demonstrate traffic-volume, resource-exhaustion or rate-limit weaknesses where doing so could affect production availability; or

  • demanding payment, compensation or other consideration as a condition of disclosing a vulnerability.


If a test could reasonably affect service availability, customer data or another user's account, contact us before carrying it out.


Findings that may not require a security report


We are primarily interested in vulnerabilities with a demonstrable security impact.


The following findings may not be treated as security vulnerabilities unless they can be shown to create a meaningful exploitable risk:


  • missing security headers without a demonstrated exploit;

  • software or service version disclosure without an associated exploitable vulnerability;

  • clickjacking on pages that do not perform sensitive actions;

  • self-XSS that cannot affect another user;

  • informational TLS configuration observations without a practical security impact;

  • generic recommendations relating to security hardening or security best practice;

  • reports generated solely by automated vulnerability scanners without validation; and

  • issues that depend on obsolete or unsupported client software.


We may still use such reports to improve our systems, but they may be handled outside the vulnerability disclosure process.


What you can expect from Spicy Mango


When you report a vulnerability in accordance with this policy, we will:


  • treat your report in good faith and handle the information appropriately;

  • aim to acknowledge receipt within five working days;

  • aim to provide an initial assessment, status update or request for additional information within ten working days;

  • investigate and prioritise the issue according to its severity, exploitability, affected systems and potential impact;

  • keep you informed where a vulnerability requires an extended investigation or remediation period;

  • coordinate with relevant customers, suppliers or technology providers where necessary; and

  • let you know when the issue has been resolved where it is appropriate and practical to do so.


Remediation time will depend on the severity and complexity of the vulnerability, the affected architecture, the availability of mitigations and any dependencies on customers or third parties. We do not commit to a fixed remediation period through this policy.


Safe harbour


If you conduct security research in good faith, comply with this policy and make a reasonable effort to avoid harm, Spicy Mango will treat your research as authorised for the purposes of this vulnerability disclosure programme and will not initiate legal action against you solely for that research.


This safe-harbour statement does not authorise activity against systems, data or organisations that are outside Spicy Mango's control, and it does not override applicable law or the rights of third parties.


If you are uncertain whether a particular security test is permitted by this policy, contact us before proceeding.


Data protection


If you encounter personal data, customer information, credentials, secrets or other confidential information while investigating a vulnerability:


  1. stop accessing the information beyond what is necessary to establish that the vulnerability exists;

  2. do not copy, download, share or retain unnecessary information;

  3. describe the exposure in your report without including unnecessary sensitive data;

  4. protect any data that you have already obtained from unauthorised access; and

  5. securely delete retained copies when they are no longer required for coordinated remediation or when we ask you to do so.


Do not publish or share personal data, credentials, confidential information or customer information obtained through security research.


Coordinated disclosure


Please give Spicy Mango a reasonable opportunity to investigate and remediate a reported vulnerability before making technical details public.


We are happy to discuss coordinated disclosure with researchers. Where public disclosure is appropriate, we prefer to agree the timing and level of technical detail with you so that customers and users are not exposed to unnecessary risk.


If a vulnerability affects a third-party product or service, we may coordinate disclosure and remediation with the relevant supplier or maintainer.


Recognition and rewards

Spicy Mango does not currently operate a public bug bounty programme, and submitting a vulnerability report does not create an entitlement to payment or other compensation.

We may choose to acknowledge researchers who provide useful vulnerability reports, subject to their consent and the circumstances of the disclosure.


Legal and regulatory reporting

This policy is intended for the responsible disclosure of technical security vulnerabilities. It is not a channel for reporting suspected fraud, privacy complaints, general support issues, service incidents or unlawful activity.


Where a reported vulnerability creates legal, regulatory, contractual or customer-notification obligations, Spicy Mango may share relevant information with affected customers, suppliers, regulators, law enforcement or other appropriate parties.


Changes to this policy

We may update this policy as our products, services and vulnerability-management processes evolve.


The current version of this policy will be published at:

https://www.spicymango.co.uk/security


Our machine-readable vulnerability disclosure information is available at:

https://www.spicymango.co.uk/security.txt

Last updated: 16 August 2026


Spicy Mango takes the security of its systems, products and services seriously. We welcome responsible reports from security researchers and others who believe they have identified a security vulnerability in a Spicy Mango-operated service.


This policy explains how to report a vulnerability, the types of security research we consider acceptable, and what you can expect from us when you make a report.


Contact

Please report security vulnerabilities to:

security@spicymango.co.uk


If you believe the vulnerability presents an immediate and significant risk to customers, users or production services, state Critical security vulnerability in the subject line.


Please do not send vulnerability details to individual employees, public support channels or social media accounts.


Scope

This policy applies to publicly accessible systems, services and applications operated by Spicy Mango where the relevant domain or service publishes a security.txt file that references this policy.


This may include:


  • Spicy Mango corporate websites and public web applications;

  • public APIs and internet-facing services operated by Spicy Mango;

  • Spicy Mango-operated Gameday services;

  • Spicy Mango-operated AuthIDConnect services; and

  • other Spicy Mango-operated domains or services whose security.txt file points to this policy.


security.txt file applies to the hostname from which it is served. The presence of this policy on one Spicy Mango domain does not automatically bring every Spicy Mango, customer or third-party system into scope.


Customer-controlled environments, customer infrastructure, third-party services and systems operated by another organisation are outside the scope of this policy unless their own security.txt file or published security documentation explicitly states otherwise.


If you are unsure whether a system is in scope, contact us before carrying out further testing.


What to include in a report


Please provide enough information for us to understand, reproduce and assess the issue. Where possible, include:


  • the affected hostname, URL, API endpoint, application or service;

  • a clear description of the vulnerability and its potential impact;

  • the steps required to reproduce the issue;

  • any relevant request and response examples;

  • screenshots, logs or proof-of-concept material where useful;

  • the date and time the issue was observed;

  • whether you believe the vulnerability has been exploited or is being actively exploited; and

  • your preferred contact details for follow-up.


Please remove or redact credentials, access tokens, personal data and other sensitive information unless it is essential to demonstrate the vulnerability.


Responsible security research


We support good-faith security research carried out carefully and proportionately.

When investigating a potential vulnerability:


  • make a reasonable effort to avoid privacy violations, degradation of service, disruption to production systems and damage to data;

  • use the minimum level of access and interaction required to demonstrate the issue;

  • stop testing and report the issue if you gain unintended access to personal data, confidential information, credentials, secrets or another user's account;

  • do not retain, download, copy or exfiltrate more data than is necessary to demonstrate the vulnerability;

  • keep information obtained during your research secure;

  • use accounts and data that you own or are authorised to use wherever possible; and

  • report the vulnerability to us promptly after confirming it.


Activities outside this policy


This policy does not authorise:


  • denial-of-service or distributed denial-of-service testing;

  • high-volume, destructive, invasive or availability-impacting automated scanning;

  • deliberate degradation, interruption or exhaustion of a service or its resources;

  • modification, deletion, corruption or destruction of data;

  • accessing, downloading or retaining unnecessary personal, customer or confidential data;

  • accessing another user's account beyond the minimum necessary to demonstrate an access-control issue;

  • credential stuffing, password spraying or large-scale brute-force testing;

  • phishing, social engineering or impersonation of Spicy Mango employees, customers, suppliers or users;

  • physical attacks against offices, staff, infrastructure or data centres;

  • malware deployment, persistence, ransomware or destructive payloads;

  • attacks against third-party suppliers, customers or infrastructure that Spicy Mango does not operate;

  • testing intended primarily to demonstrate traffic-volume, resource-exhaustion or rate-limit weaknesses where doing so could affect production availability; or

  • demanding payment, compensation or other consideration as a condition of disclosing a vulnerability.


If a test could reasonably affect service availability, customer data or another user's account, contact us before carrying it out.


Findings that may not require a security report


We are primarily interested in vulnerabilities with a demonstrable security impact.


The following findings may not be treated as security vulnerabilities unless they can be shown to create a meaningful exploitable risk:


  • missing security headers without a demonstrated exploit;

  • software or service version disclosure without an associated exploitable vulnerability;

  • clickjacking on pages that do not perform sensitive actions;

  • self-XSS that cannot affect another user;

  • informational TLS configuration observations without a practical security impact;

  • generic recommendations relating to security hardening or security best practice;

  • reports generated solely by automated vulnerability scanners without validation; and

  • issues that depend on obsolete or unsupported client software.


We may still use such reports to improve our systems, but they may be handled outside the vulnerability disclosure process.


What you can expect from Spicy Mango


When you report a vulnerability in accordance with this policy, we will:


  • treat your report in good faith and handle the information appropriately;

  • aim to acknowledge receipt within five working days;

  • aim to provide an initial assessment, status update or request for additional information within ten working days;

  • investigate and prioritise the issue according to its severity, exploitability, affected systems and potential impact;

  • keep you informed where a vulnerability requires an extended investigation or remediation period;

  • coordinate with relevant customers, suppliers or technology providers where necessary; and

  • let you know when the issue has been resolved where it is appropriate and practical to do so.


Remediation time will depend on the severity and complexity of the vulnerability, the affected architecture, the availability of mitigations and any dependencies on customers or third parties. We do not commit to a fixed remediation period through this policy.


Safe harbour


If you conduct security research in good faith, comply with this policy and make a reasonable effort to avoid harm, Spicy Mango will treat your research as authorised for the purposes of this vulnerability disclosure programme and will not initiate legal action against you solely for that research.


This safe-harbour statement does not authorise activity against systems, data or organisations that are outside Spicy Mango's control, and it does not override applicable law or the rights of third parties.


If you are uncertain whether a particular security test is permitted by this policy, contact us before proceeding.


Data protection


If you encounter personal data, customer information, credentials, secrets or other confidential information while investigating a vulnerability:


  1. stop accessing the information beyond what is necessary to establish that the vulnerability exists;

  2. do not copy, download, share or retain unnecessary information;

  3. describe the exposure in your report without including unnecessary sensitive data;

  4. protect any data that you have already obtained from unauthorised access; and

  5. securely delete retained copies when they are no longer required for coordinated remediation or when we ask you to do so.


Do not publish or share personal data, credentials, confidential information or customer information obtained through security research.


Coordinated disclosure


Please give Spicy Mango a reasonable opportunity to investigate and remediate a reported vulnerability before making technical details public.


We are happy to discuss coordinated disclosure with researchers. Where public disclosure is appropriate, we prefer to agree the timing and level of technical detail with you so that customers and users are not exposed to unnecessary risk.


If a vulnerability affects a third-party product or service, we may coordinate disclosure and remediation with the relevant supplier or maintainer.


Recognition and rewards

Spicy Mango does not currently operate a public bug bounty programme, and submitting a vulnerability report does not create an entitlement to payment or other compensation.

We may choose to acknowledge researchers who provide useful vulnerability reports, subject to their consent and the circumstances of the disclosure.


Legal and regulatory reporting

This policy is intended for the responsible disclosure of technical security vulnerabilities. It is not a channel for reporting suspected fraud, privacy complaints, general support issues, service incidents or unlawful activity.


Where a reported vulnerability creates legal, regulatory, contractual or customer-notification obligations, Spicy Mango may share relevant information with affected customers, suppliers, regulators, law enforcement or other appropriate parties.


Changes to this policy

We may update this policy as our products, services and vulnerability-management processes evolve.


The current version of this policy will be published at:

https://www.spicymango.co.uk/security


Our machine-readable vulnerability disclosure information is available at:

https://www.spicymango.co.uk/security.txt

Last updated: 16 August 2026


Spicy Mango takes the security of its systems, products and services seriously. We welcome responsible reports from security researchers and others who believe they have identified a security vulnerability in a Spicy Mango-operated service.


This policy explains how to report a vulnerability, the types of security research we consider acceptable, and what you can expect from us when you make a report.


Contact

Please report security vulnerabilities to:

security@spicymango.co.uk


If you believe the vulnerability presents an immediate and significant risk to customers, users or production services, state Critical security vulnerability in the subject line.


Please do not send vulnerability details to individual employees, public support channels or social media accounts.


Scope

This policy applies to publicly accessible systems, services and applications operated by Spicy Mango where the relevant domain or service publishes a security.txt file that references this policy.


This may include:


  • Spicy Mango corporate websites and public web applications;

  • public APIs and internet-facing services operated by Spicy Mango;

  • Spicy Mango-operated Gameday services;

  • Spicy Mango-operated AuthIDConnect services; and

  • other Spicy Mango-operated domains or services whose security.txt file points to this policy.


security.txt file applies to the hostname from which it is served. The presence of this policy on one Spicy Mango domain does not automatically bring every Spicy Mango, customer or third-party system into scope.


Customer-controlled environments, customer infrastructure, third-party services and systems operated by another organisation are outside the scope of this policy unless their own security.txt file or published security documentation explicitly states otherwise.


If you are unsure whether a system is in scope, contact us before carrying out further testing.


What to include in a report


Please provide enough information for us to understand, reproduce and assess the issue. Where possible, include:


  • the affected hostname, URL, API endpoint, application or service;

  • a clear description of the vulnerability and its potential impact;

  • the steps required to reproduce the issue;

  • any relevant request and response examples;

  • screenshots, logs or proof-of-concept material where useful;

  • the date and time the issue was observed;

  • whether you believe the vulnerability has been exploited or is being actively exploited; and

  • your preferred contact details for follow-up.


Please remove or redact credentials, access tokens, personal data and other sensitive information unless it is essential to demonstrate the vulnerability.


Responsible security research


We support good-faith security research carried out carefully and proportionately.

When investigating a potential vulnerability:


  • make a reasonable effort to avoid privacy violations, degradation of service, disruption to production systems and damage to data;

  • use the minimum level of access and interaction required to demonstrate the issue;

  • stop testing and report the issue if you gain unintended access to personal data, confidential information, credentials, secrets or another user's account;

  • do not retain, download, copy or exfiltrate more data than is necessary to demonstrate the vulnerability;

  • keep information obtained during your research secure;

  • use accounts and data that you own or are authorised to use wherever possible; and

  • report the vulnerability to us promptly after confirming it.


Activities outside this policy


This policy does not authorise:


  • denial-of-service or distributed denial-of-service testing;

  • high-volume, destructive, invasive or availability-impacting automated scanning;

  • deliberate degradation, interruption or exhaustion of a service or its resources;

  • modification, deletion, corruption or destruction of data;

  • accessing, downloading or retaining unnecessary personal, customer or confidential data;

  • accessing another user's account beyond the minimum necessary to demonstrate an access-control issue;

  • credential stuffing, password spraying or large-scale brute-force testing;

  • phishing, social engineering or impersonation of Spicy Mango employees, customers, suppliers or users;

  • physical attacks against offices, staff, infrastructure or data centres;

  • malware deployment, persistence, ransomware or destructive payloads;

  • attacks against third-party suppliers, customers or infrastructure that Spicy Mango does not operate;

  • testing intended primarily to demonstrate traffic-volume, resource-exhaustion or rate-limit weaknesses where doing so could affect production availability; or

  • demanding payment, compensation or other consideration as a condition of disclosing a vulnerability.


If a test could reasonably affect service availability, customer data or another user's account, contact us before carrying it out.


Findings that may not require a security report


We are primarily interested in vulnerabilities with a demonstrable security impact.


The following findings may not be treated as security vulnerabilities unless they can be shown to create a meaningful exploitable risk:


  • missing security headers without a demonstrated exploit;

  • software or service version disclosure without an associated exploitable vulnerability;

  • clickjacking on pages that do not perform sensitive actions;

  • self-XSS that cannot affect another user;

  • informational TLS configuration observations without a practical security impact;

  • generic recommendations relating to security hardening or security best practice;

  • reports generated solely by automated vulnerability scanners without validation; and

  • issues that depend on obsolete or unsupported client software.


We may still use such reports to improve our systems, but they may be handled outside the vulnerability disclosure process.


What you can expect from Spicy Mango


When you report a vulnerability in accordance with this policy, we will:


  • treat your report in good faith and handle the information appropriately;

  • aim to acknowledge receipt within five working days;

  • aim to provide an initial assessment, status update or request for additional information within ten working days;

  • investigate and prioritise the issue according to its severity, exploitability, affected systems and potential impact;

  • keep you informed where a vulnerability requires an extended investigation or remediation period;

  • coordinate with relevant customers, suppliers or technology providers where necessary; and

  • let you know when the issue has been resolved where it is appropriate and practical to do so.


Remediation time will depend on the severity and complexity of the vulnerability, the affected architecture, the availability of mitigations and any dependencies on customers or third parties. We do not commit to a fixed remediation period through this policy.


Safe harbour


If you conduct security research in good faith, comply with this policy and make a reasonable effort to avoid harm, Spicy Mango will treat your research as authorised for the purposes of this vulnerability disclosure programme and will not initiate legal action against you solely for that research.


This safe-harbour statement does not authorise activity against systems, data or organisations that are outside Spicy Mango's control, and it does not override applicable law or the rights of third parties.


If you are uncertain whether a particular security test is permitted by this policy, contact us before proceeding.


Data protection


If you encounter personal data, customer information, credentials, secrets or other confidential information while investigating a vulnerability:


  1. stop accessing the information beyond what is necessary to establish that the vulnerability exists;

  2. do not copy, download, share or retain unnecessary information;

  3. describe the exposure in your report without including unnecessary sensitive data;

  4. protect any data that you have already obtained from unauthorised access; and

  5. securely delete retained copies when they are no longer required for coordinated remediation or when we ask you to do so.


Do not publish or share personal data, credentials, confidential information or customer information obtained through security research.


Coordinated disclosure


Please give Spicy Mango a reasonable opportunity to investigate and remediate a reported vulnerability before making technical details public.


We are happy to discuss coordinated disclosure with researchers. Where public disclosure is appropriate, we prefer to agree the timing and level of technical detail with you so that customers and users are not exposed to unnecessary risk.


If a vulnerability affects a third-party product or service, we may coordinate disclosure and remediation with the relevant supplier or maintainer.


Recognition and rewards

Spicy Mango does not currently operate a public bug bounty programme, and submitting a vulnerability report does not create an entitlement to payment or other compensation.

We may choose to acknowledge researchers who provide useful vulnerability reports, subject to their consent and the circumstances of the disclosure.


Legal and regulatory reporting

This policy is intended for the responsible disclosure of technical security vulnerabilities. It is not a channel for reporting suspected fraud, privacy complaints, general support issues, service incidents or unlawful activity.


Where a reported vulnerability creates legal, regulatory, contractual or customer-notification obligations, Spicy Mango may share relevant information with affected customers, suppliers, regulators, law enforcement or other appropriate parties.


Changes to this policy

We may update this policy as our products, services and vulnerability-management processes evolve.


The current version of this policy will be published at:

https://www.spicymango.co.uk/security


Our machine-readable vulnerability disclosure information is available at:

https://www.spicymango.co.uk/security.txt