Security
Report a security issue
Please report potential vulnerabilities privately so they can be investigated without putting members or the service at risk.
How to report
Good-faith reports are welcome. Email contact@catchmed.co.uk with a concise description, the affected page or feature, and safe reproduction steps. Do not include personal data you do not own.
Responsible testing
Please do not access another person's account or data, exfiltrate data, use destructive techniques, disrupt the service, use automated high-volume testing, bypass access controls, send emails, change records, or publicly disclose an unresolved issue. Use only accounts and data you control.
What to expect
CatchMed will acknowledge reports where possible, assess their impact, and prioritise proportionate fixes. This is not a paid bug-bounty programme and no reward is promised.
