Red Horizon Cyber Group | Policy Version 1.0 | Last Updated: 2nd September 2026
Reporting Address security@redhorizoncybergroup.com
Reporting a Security Vulnerability
Red Horizon Cyber Group values responsible reports from people who identify potential security vulnerabilities in our public digital services. This policy explains how to report a concern, what information to provide, the limits of permitted activity, and what you can expect from us.
IMPORTANT: This policy provides a route for responsible reporting. It does not create a public bug-bounty programme or give general permission to test, scan, access or interfere with Red Horizon systems.
01 - SCOPE
This policy applies only to public-facing websites, applications and digital services owned and operated by Red Horizon Cyber Group that expressly link to this policy or are identified in a Red Horizon security.txt file.
The following are outside scope unless Red Horizon gives you prior written authorisation:
- Systems, networks, accounts, data or applications belonging to Red Horizon clients, partners, suppliers, staff members or other third parties.
- Third-party products or services used by Red Horizon, including hosting, cloud, communications, payment, analytics and software-as-a-service providers.
- Development, staging, test or preview environments that do not expressly link to this policy or appear in an applicable security.txt file.
- Physical premises, employees, contractors, social-media accounts and telephone or email systems.
If you are unsure whether an asset is in scope, email security@redhorizoncybergroup.com and wait for written confirmation before taking any further action.
02 - REPORTING A VULNERABILITY
Please report suspected vulnerabilities privately by email to: security@redhorizoncybergroup.com
Use the subject line “Security Vulnerability Report” and include “URGENT” only where you reasonably believe there is an active compromise, immediate risk to users, or a vulnerability likely to cause serious harm.
03 - INFORMATION TO INCLUDE
Please provide enough information for us to understand, reproduce and assess the issue. Where possible, include:
- Your name or preferred identifier and a reliable contact email address. Anonymous reports are accepted, although we may be unable to ask follow-up questions.
- The affected website, hostname, URL, application, feature or service.
- A concise description of the suspected vulnerability and its potential security impact.
- The date and time you observed the issue, including your time zone.
- Clear, repeatable steps using a benign and non-destructive proof of concept.
- Relevant request and response details, screenshots or logs, with passwords, tokens, personal data and other secrets removed or redacted.
- Any reasonable remediation suggestion, if known.
Do not send large quantities of personal, confidential or sensitive data by ordinary email. Tell us what you found and we will arrange a more appropriate transfer method if additional material is genuinely required.
04 - RESPONSIBLE RESEARCH GUIDELINES
If you encounter a potential vulnerability during ordinary, lawful use of a service, limit any validation to the minimum non-destructive activity needed to establish that a genuine issue may exist. You must:
- Act in good faith and comply with all applicable laws and this policy.
- Stop immediately if you access, or appear able to access, another person’s account, personal data, confidential information or production records.
- Do not copy, download, retain, alter, delete, disclose or use any data that is not your own. Include only the minimum redacted evidence needed for us to locate the issue.
- Avoid privacy violations, disruption, degradation of service, financial loss and harm to Red Horizon or any third party.
- Report the issue promptly and keep all vulnerability information confidential while we investigate and remediate it.
- Follow any reasonable instructions we give to protect users, evidence or affected systems
05 - PROHIBITED ACTIVITIES
You must not:
- Use denial-of-service, distributed denial-of-service, stress-testing or resource-exhaustion techniques.
- Use high-volume, invasive or destructive automated scanning, fuzzing, brute force, credential stuffing or password spraying.
- Deploy malware, ransomware, backdoors, web shells, persistence mechanisms or command-and-control infrastructure.
- Use phishing, social engineering, impersonation, pretexting, spam or attacks against Red Horizon personnel, clients, suppliers or partners.
- Access accounts or data belonging to another person; bypass authentication for access beyond your own authorised account; or escalate privileges beyond the minimum necessary to demonstrate a suspected issue.
- Modify, corrupt, encrypt, delete, exfiltrate or make unnecessary copies of data, files, configurations or code.
- Pivot to other systems, establish persistence, maintain access, chain vulnerabilities beyond what is necessary for a minimal proof of concept, or exploit a vulnerability for financial gain or any other purpose.
- Test physical security, telephone systems, offices, employees, contractors, clients, suppliers or any third-party service.
- Make extortionate or coercive demands; use threats to obtain payment, employment, commercial work or another benefit; or condition confidentiality on receiving such a benefit.
06 - WHAT YOU CAN EXPECT FROM RED HORIZON
When we receive a report that contains sufficient information, we aim to:
- Acknowledge receipt within five working days.
- Complete an initial triage or assessment within ten working days, where reasonably practicable.
- Communicate respectfully and request clarification where required.
- Prioritise remediation by considering impact, likelihood, severity, exploitability and the needs of affected users.
- Provide reasonable progress updates where it is safe and appropriate to do so.
- Tell you when we consider the issue resolved or otherwise closed, subject to legal, operational and confidentiality restrictions.
Some reports may require longer investigation or remediation. Our response targets are aims, not guarantees, and may vary with severity, complexity, third-party dependencies and operational risk. Please avoid requesting a status update more than once every fourteen days unless new evidence indicates an urgent change in risk.
07 - COORDINATED DISCLOSURE AND CONFIDENTIALITY
Do not publish, share or discuss the vulnerability, affected systems, proof-of-concept material or related correspondence while the issue is under active investigation or remediation without Red Horizon’s prior written agreement. We ask reporters to allow reasonable time for investigation and remediation before any disclosure is considered.
If disclosure may be appropriate after remediation, contact us so that timing and content can be coordinated. Red Horizon may withhold information where disclosure could create risk, breach confidentiality, expose personal data, compromise a client or third party, prejudice an investigation, or conflict with legal or regulatory obligations.
08 - SAFE HARBOUR AND LEGAL POSITION
Where you act in good faith, remain within the express scope and restrictions of this policy, stop when required, and report the issue promptly, Red Horizon does not intend to initiate civil legal action solely in respect of that compliant activity.
This statement is limited. It does not provide immunity, indemnity or permission to break the law; it does not waive Red Horizon’s rights; and it cannot bind law-enforcement bodies, regulators, courts, clients, suppliers or other third parties. Red Horizon reserves all rights in relation to conduct that falls outside this policy or causes harm.
If you are uncertain whether planned activity would comply with this policy, ask us first and wait for express written authorisation. Acknowledging or investigating a report does not retrospectively authorise prohibited activity.
09 - REWARDS AND RECOGNITION
Red Horizon Cyber Group does not currently operate a public bug-bounty programme and does not offer monetary rewards, free services, employment, contracts or other compensation for vulnerability reports. Do not incur costs on the assumption that they will be reimbursed.
We may, at our sole discretion and with the reporter’s consent, acknowledge a particularly helpful report. Any acknowledgement does not create an entitlement or establish a precedent for future reports.
10 - PERSONAL DATA
We will use the information you provide to receive, assess, investigate, remediate and document the reported vulnerability; communicate with you; protect our systems and users; and meet legal, regulatory, contractual and security obligations.
Your report may be shared on a need-to-know basis with relevant Red Horizon personnel, professional advisers, service providers, affected clients or suppliers, law enforcement, regulators, or other parties where necessary and lawful. Personal data will be handled in accordance with Red Horizon’s Privacy Policy.
11 - OTHER REPORTS
This address is for suspected vulnerabilities affecting Red Horizon-owned digital services. It is not a route for requesting penetration testing, reporting a security issue in a client’s system, seeking technical support, making a complaint, or reporting general cybercrime. Please use the appropriate contact channel on the Red Horizon website for those matters.
If you believe a system is actively compromised or a cyber incident presents an immediate risk to life, safety or essential services, contact the relevant system owner and the appropriate emergency, law-enforcement or national cyber-security authority.
12 - POLICY CHANGES AND CONTACT
Red Horizon Cyber Group may update this policy from time to time. The version published on our website at the time of a report will apply to that report unless we agree otherwise in writing.
Security Vulnerability Reports: security@redhorizoncybergroup.com
Organisation: Red Horizon Cyber Group