Skip to content

Security Disclosure Policy

Last updated: July 2026

Closed beta. This policy applies to RouteRelay during the closed beta period. It is written in plain English and has not been reviewed by a solicitor. A fuller, legally-reviewed disclosure policy will be published before any wider public launch.

Reporting a vulnerability

If you believe you have found a security vulnerability in RouteRelay, please tell us at security@routerelay.co.uk. A description of what you found and the steps to reproduce it is the most useful thing you can send.

What happens next

  • We acknowledge receipt within 48 hours.
  • We aim to resolve confirmed issues within 30 days.

What we ask of you

Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and remediate it.

Machine-readable version

The same contact details are published under RFC 9116 at /.well-known/security.txt.

Related

See also our Privacy Policy and Terms of Service.