Trust Centre

Responsible disclosure policy

If you have found a security problem in InvestorUniverse, this page says how to tell us and what happens next.

I. AI LTD trading as InvestorUniverse

How to report

Send your report to privacy@investoruniverse.uk. This is our privacy mailbox, which is the published contact for security reports. The same contact is published in security.txt. Write in English.

A report we can act on has:

  • The address or feature affected, and the account you used if you were signed in.
  • The steps to reproduce it, with the request and response where you have them.
  • What you think someone could do with it.
  • How you would like to be credited, if at all.

Scope

In scope:

  • The website and application at www.investoruniverse.uk, including its sign-in, accounts, payments flow and API.
  • Anything that exposes another account's data, or an investor's contact details, to someone not entitled to them.

Out of scope:

  • Services run by other companies, such as our payment provider's pages. Report those to their owner.
  • Denial of service, and any test that sends enough traffic to slow the site for others.
  • Social engineering of our staff or customers, and physical attacks.
  • Reports from automated scanners with no demonstrated impact.
  • Missing best-practice settings with no route to exploit them.

What we ask of you

  • Use only accounts you own, or accounts whose owner has agreed.
  • Stop at the point where the problem is proved. Do not read, copy, change or delete data that is not yours. If you come across someone else's data, tell us and do not keep it.
  • Do not collect investor contact details in bulk to prove a point. One record is enough.
  • Give us a reasonable time to fix the problem before you tell anyone else about it.
  • Keep to the law where you are and in the UK.

The site blocks automated clients on investor data pages and locks accounts that behave like a scraper. A block on a network address lasts 24 hours. If your testing triggers one, say so in your report.

What we commit to

  • We will confirm that we received your report.
  • We will tell you whether we could reproduce it and what we intend to do.
  • We will tell you when it is fixed.
  • We will credit you if you want us to, once it is fixed.
  • We will not take legal action against you for research that keeps to this policy. We cannot speak for anyone else, and this policy does not change what the law requires of you.

We do not pay rewards for reports, and there is no bug bounty. If a problem affects personal data, we handle it under our duties as a data controller as well as under this policy.

Trust Centre · Security overview · System status