SelfSubmit is designed to help you stay compliant with HMRC Making Tax Digital requirements. You remain responsible for ensuring the information you submit is accurate.

Responsible disclosure policy

We welcome reports of genuine security vulnerabilities. Please follow this policy so we can fix issues safely.

Last updated: 6 July 2026

1. We appreciate responsible reports

If you believe you have found a security vulnerability in selfsubmit.co.uk or the SelfSubmit application, please tell us privately before disclosing it publicly. We will investigate in good faith.

2. How to report

Email support@selfsubmit.co.uk with:

  • A clear description of the issue and affected URLs or features
  • Steps to reproduce (proof-of-concept where helpful)
  • Your assessment of impact (confidentiality, integrity, availability)
  • Your contact details for follow-up

Please encrypt sensitive attachments if you use them — ask us for a PGP key if required.

3. Please do

  • Act in good faith and avoid privacy violations
  • Test only against accounts you own or our explicit written authorisation
  • Give us reasonable time to remediate before public disclosure
  • Comply with applicable laws

4. Please do not

  • Access, modify, or delete other users' data
  • Perform denial-of-service attacks or social engineering against our staff or users
  • Exploit vulnerabilities beyond what is needed to demonstrate the issue
  • Demand payment before reporting (we do not operate a paid bug bounty at this time)

5. Our process

  1. Acknowledge receipt within three working days where possible
  2. Investigate and prioritise by severity
  3. Keep you informed of material progress
  4. Notify you when we believe the issue is fixed

6. Safe harbour

If you follow this policy and act in good faith, we will not pursue legal action against you for research activities that were necessary to report the vulnerability. This does not extend to conduct outside the policy (for example data theft or extortion).

7. Recognition

We may thank researchers privately or with permission on a security acknowledgements page. We do not currently offer monetary rewards.