Vulnerability Disclosure Policy
Applies to: Security research and reports affecting official TerraAqua products and services
1. Purpose
TerraAqua welcomes responsible reports from security researchers, customers and members of the public who believe they have identified a vulnerability affecting a TerraAqua product or service.
2. Scope
This policy applies to:
- TerraAqua websites and customer portals;
- TerraAqua Cloud services and APIs;
- ReefCore controller software and firmware;
- official TerraAqua mobile or web applications; and
- official TerraAqua networked sensor nodes and update mechanisms.
3. Reporting
Send reports to info@terra-aqua.co.uk with the subject line Security Vulnerability Report.
Include, where available:
- the affected product, service, version or URL;
- a clear description of the issue;
- reproduction steps;
- proof-of-concept information;
- the potential impact;
- suggested remediation or mitigation; and
- your preferred contact details.
4. Protecting information
Do not send passwords, full personal datasets, authentication tokens or other unnecessary sensitive information. If sensitive evidence is required, ask TerraAqua to agree a secure transfer method first.
5. Good-faith research
Research should be carried out in good faith and only to the minimum extent necessary to demonstrate the issue. Researchers must not:
- access, alter, copy or delete another person's data;
- cause service disruption or denial of service;
- deploy malware, ransomware or persistence mechanisms;
- use social engineering, phishing or physical intrusion;
- conduct high-volume automated testing likely to affect service;
- access production data beyond what is necessary to confirm the issue; or
- use a vulnerability for financial gain, extortion or unlawful activity.
6. Test accounts and owned devices
Where possible, testing should be limited to accounts and hardware owned or expressly authorised by the researcher. Stop testing immediately if customer information, safety-critical operation or service stability may be affected.
7. Coordinated disclosure
Please allow TerraAqua a reasonable opportunity to investigate and remediate a reported vulnerability before public disclosure. Disclosure timing should take account of severity, fix availability, customer deployment and any active exploitation.
8. TerraAqua's response
TerraAqua will acknowledge receipt of a security vulnerability report within 5 working days.
TerraAqua will provide an initial status update within 10 working days after acknowledgement. Further status updates will be provided at least every 30 calendar days until the issue is resolved or formally closed, unless a different communication schedule is agreed with the reporter.
Urgent, actively exploited or safety-related issues may receive more frequent communication. These targets concern acknowledgement and communication; they do not guarantee that every issue can be fully corrected within a fixed period.
9. Safe-harbour approach
TerraAqua does not intend to pursue legal action against a researcher for accidental, good-faith activity that follows this policy, avoids harm, respects privacy and complies with applicable law. This statement does not authorise unlawful activity or bind third parties.
10. Rewards
TerraAqua does not currently operate a guaranteed bug-bounty programme. Reports are voluntary unless TerraAqua has expressly agreed a reward in writing before submission.
11. Out-of-scope findings
The following are normally outside scope unless they create a demonstrated security risk:
- missing security headers without exploitable impact;
- self-cross-site scripting;
- clickjacking on pages with no sensitive action;
- rate-limit observations without practical abuse;
- outdated browser support;
- social-engineering scenarios; and
- issues affecting only unsupported or modified installations.
12. Privacy and recognition
Reporter contact information will be used to investigate and respond to the report. TerraAqua will not publicly identify or credit a reporter without permission.
13. Urgent incidents
If active exploitation, customer-data exposure or an immediate safety risk is suspected, mark the report as urgent and explain the evidence clearly.
14. Contact
Reports should be sent to info@terra-aqua.co.uk.
Version history
| Version | Date | Description |
|---|---|---|
| 1.0 | 21 July 2026 | Initial commercial release |
| 1.1 | 5 August 2026 | Added definite acknowledgement and ongoing status-update times for security reports. |