Security Disclosure Policy
Last updated: July 2026
Closed beta. This policy applies to RouteRelay during the closed beta period. It is written in plain English and has not been reviewed by a solicitor. A fuller, legally-reviewed disclosure policy will be published before any wider public launch.
Reporting a vulnerability
If you believe you have found a security vulnerability in RouteRelay, please tell us at security@routerelay.co.uk. A description of what you found and the steps to reproduce it is the most useful thing you can send.
What happens next
- We acknowledge receipt within 48 hours.
- We aim to resolve confirmed issues within 30 days.
What we ask of you
Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and remediate it.
Machine-readable version
The same contact details are published under RFC 9116 at /.well-known/security.txt.
Related
See also our Privacy Policy and Terms of Service.