Skip to main content
Pentesys
01FoundationGet Cyber Essentials Ready02ExposeSee and Prioritise Your External Exposure03ValidateProve What Can Be Exploited04AdversaryPressure-Test Your Real-World Defences
Why PentesysPricingInsightsGlossaryCompany
sales@pentesys.comTake the two-minute security check →Portal loginLogin ↗
Solutions01FoundationGet Cyber Essentials Ready02ExposeSee and Prioritise Your External Exposure03ValidateProve What Can Be Exploited04AdversaryPressure-Test Your Real-World Defences
Why PentesysPricingInsightsGlossaryCheck your security prioritiesContactCompany
Explore the Pentesys Portal →Existing customer portal login ↗sales@pentesys.comCheck your security priorities →
  1. Home
  2. /Legal
  3. /Vulnerability Disclosure Policy

Pentesys legal

Vulnerability Disclosure Policy

How to report a suspected security weakness affecting Pentesys-controlled systems safely and responsibly.

Last updated: 11 August 2026
On this pageOur commitmentHow to reportResearch guidelinesOut of scopeGood-faith research

Our commitment

Pentesys values good-faith security research. If you believe you have found a vulnerability in a Pentesys-controlled public system, please tell us promptly and give us a reasonable opportunity to investigate and remediate it before public disclosure.

How to report

Email sales@pentesys.com with “Security vulnerability” in the subject line. Include the affected asset, a clear description, reproduction steps, potential impact and any supporting evidence. Do not include unnecessary personal data or active malware. We will acknowledge valid reports and keep you informed where reasonably possible.

Research guidelines

  • Act in good faith and only test Pentesys-controlled assets that are publicly accessible.
  • Stop immediately if you encounter personal data, customer data, credentials or evidence of active compromise, and report what you found.
  • Use the minimum testing needed to demonstrate the issue.
  • Do not disrupt services, degrade availability, alter or destroy data, access another person’s account, use social engineering, conduct denial-of-service testing or install persistent access.
  • Do not demand payment or make public disclosure before Pentesys has had a reasonable opportunity to respond.

Out of scope

Third-party services, customer systems, physical testing, social engineering, automated high-volume scanning, denial-of-service activity and findings that are purely informational without a credible security impact are out of scope unless Pentesys has given explicit written authorisation.

Good-faith research

Where research follows this policy, Pentesys will treat it as authorised for the limited purpose of reporting the vulnerability and will not intentionally pursue legal action. This statement does not authorise activity that is unlawful, affects third parties or falls outside this policy, and it cannot bind third parties.

Need to contact Pentesys?

sales@pentesys.comUse the contact form →
Pentesys

AI-driven coverage. Human-verified security.

UK-based cybersecurity expertise for organisations that need clearer, continuous assurance.

Follow PentesysinLinkedIn
SolutionsPentesys PortalFoundationExposeValidateAdversaryCheck your security priorities
ResourcesCompanyWhy PentesysPricingInsightsCyber glossaryContact ussales@pentesys.com
LegalPrivacy policyCookie policyTerms & conditionsVulnerability disclosureModern slavery statement

Pentesys Ltd is a company registered in England and Wales under company number 15041337.

Registered office: 8 Church Green East, Redditch, England, B98 8BP.

© 2026 Pentesys Ltd. All rights reserved.
Take the 2-minute security check →