Reporting a security issue

We build software that handles people's tax records. Keeping that data safe matters to us, and we would much rather hear about a problem than not.

If you believe you have found a security vulnerability in our website or in any of our software, please tell us using the details below. This page explains how to report, what we will do, and what we ask of you in return.

How to report

security@abcsa.co.uk is a monitored inbox that comes straight to us.

Please include as much of the following as you can:

  • What the issue is, and why you think it is a security problem
  • Step-by-step instructions to reproduce it
  • Where you found it — the URL, or the product name, version and operating system
  • What an attacker could realistically do with it
  • Any proof-of-concept code, screenshots or logs
  • How you would like to be credited, if at all

Please do not include real taxpayer data in your report. If you need to illustrate the issue with data, redact National Insurance numbers, UTRs and any other identifiers, or use test values.

If you would prefer to send the report encrypted, email us first and we will arrange it.

What we will do

  • We will acknowledge your report within 3 working days.
  • We will tell you our initial assessment — whether we have reproduced it, and how serious we think it is — within 10 working days.
  • We will keep you updated at least every 20 working days until the issue is closed.
  • We will let you know when the issue is fixed, and we will credit you publicly if you would like us to.

We do not currently run a paid bug bounty programme, so we cannot offer a reward.

Where an issue affects HMRC data or HMRC systems, we will report it to HMRC. Where personal data has been put at risk, we will assess it and notify the Information Commissioner's Office and affected individuals where the law requires.

What is in scope

  • The website at abcsa.co.uk and its subdomains
  • Our desktop applications: ABC Digital Tax, ABC VAT Bridge, ABC SA100 and ABC SA800
  • Our licensing and update services

What is out of scope

  • HMRC's own systems and APIs. If the issue is in an HMRC service rather than in our software, please report it to HMRC directly. You are welcome to tell us as well.
  • Third-party services we use — for example our payment and storefront providers. Please report those to the provider. Again, do tell us too.
  • Social engineering of our staff, our customers or our suppliers
  • Physical attacks, or attacks on anyone's personal property or accounts
  • Denial-of-service testing, load testing or anything else that degrades the service for other people
  • Raw output from an automated scanner, with no working demonstration of impact
  • Missing HTTP security headers, weak TLS cipher suites, cookie flags, or email configuration (SPF, DKIM, DMARC) reported without a demonstrated exploit. We are happy to hear about these, but we will treat them as hardening suggestions rather than vulnerabilities.
  • Anything that requires an already-compromised device or an already-stolen credential

What we ask of you

If you are testing, please:

  • Use only your own accounts, or test data you created yourself
  • Stop as soon as you have confirmed a vulnerability exists — do not go further into the system than you need to in order to demonstrate it
  • Never access, change, delete or keep data belonging to anyone else. If you come across someone else's data by accident, stop, and tell us what you saw so we can assess it
  • Do not degrade, interrupt or overload our services or anyone else's
  • Give us a reasonable opportunity to fix the issue before you tell anyone else about it. We would suggest 90 days from your report, but talk to us — we are a small team and we would rather agree a timescale with you than guess
  • Do not use your findings to demand payment from us. A report that arrives with a price attached is an extortion attempt, and we will treat it as one

Our commitment to you

If you follow this policy in good faith, we will:

  • Treat your research as authorised, and will not initiate or support legal action against you in relation to it
  • Work with you to understand and resolve the issue quickly
  • Not pass your details to anyone else without your permission, unless we are legally required to

We cannot waive the rights of third parties. If your testing affects a service we do not control, this policy cannot protect you in respect of that service.

If you are a customer and think your data is at risk

Email security@abcsa.co.uk and put URGENT in the subject line. Tell us what has happened and how we can reach you, and we will come back to you as quickly as we can.


Your basket
Subtotal
£0.00

VAT will be added at the final part of payment processing, based on your location