TerraAqua Legal Centre

Vulnerability Disclosure Policy

Document IDTA-LC-011
Version1.0
Effective date21 July 2026
Last reviewed21 July 2026
OwnerTerraAqua
ClassificationPublic

Applies to: Security research and reports affecting official TerraAqua products and services

1. Purpose

TerraAqua welcomes responsible reports from security researchers, customers and members of the public who believe they have identified a vulnerability affecting a TerraAqua product or service.

2. Scope

This policy applies to:

3. Reporting

Send reports to info@terra-aqua.co.uk with the subject line Security Vulnerability Report.

Include, where available:

4. Protecting information

Do not send passwords, full personal datasets, authentication tokens or other unnecessary sensitive information. If sensitive evidence is required, ask TerraAqua to agree a secure transfer method first.

5. Good-faith research

Research should be carried out in good faith and only to the minimum extent necessary to demonstrate the issue. Researchers must not:

6. Test accounts and owned devices

Where possible, testing should be limited to accounts and hardware owned or expressly authorised by the researcher. Stop testing immediately if customer information, safety-critical operation or service stability may be affected.

7. Coordinated disclosure

Please allow TerraAqua a reasonable opportunity to investigate and remediate a reported vulnerability before public disclosure. Disclosure timing should take account of severity, fix availability, customer deployment and any active exploitation.

8. TerraAqua's response

TerraAqua will acknowledge receipt of a security vulnerability report within 5 working days.

TerraAqua will provide an initial status update within 10 working days after acknowledgement. Further status updates will be provided at least every 30 calendar days until the issue is resolved or formally closed, unless a different communication schedule is agreed with the reporter.

Urgent, actively exploited or safety-related issues may receive more frequent communication. These targets concern acknowledgement and communication; they do not guarantee that every issue can be fully corrected within a fixed period.

9. Safe-harbour approach

TerraAqua does not intend to pursue legal action against a researcher for accidental, good-faith activity that follows this policy, avoids harm, respects privacy and complies with applicable law. This statement does not authorise unlawful activity or bind third parties.

10. Rewards

TerraAqua does not currently operate a guaranteed bug-bounty programme. Reports are voluntary unless TerraAqua has expressly agreed a reward in writing before submission.

11. Out-of-scope findings

The following are normally outside scope unless they create a demonstrated security risk:

12. Privacy and recognition

Reporter contact information will be used to investigate and respond to the report. TerraAqua will not publicly identify or credit a reporter without permission.

13. Urgent incidents

If active exploitation, customer-data exposure or an immediate safety risk is suspected, mark the report as urgent and explain the evidence clearly.

14. Contact

Reports should be sent to info@terra-aqua.co.uk.

Version history

VersionDateDescription
1.021 July 2026Initial commercial release
1.15 August 2026Added definite acknowledgement and ongoing status-update times for security reports.