Report Security Issues

Last updated: August 24, 2026

At Coastora, we take the security of our Website and our customers seriously.

If you believe you have discovered a security vulnerability affecting coastora.co.uk, we encourage you to report it responsibly by contacting us at support@coastora.co.uk.

We will review legitimate security reports and take reasonable steps to investigate and address confirmed vulnerabilities.

Responsible Disclosure Guidelines

When investigating or reporting a potential security issue, we ask that you:

  1. Give us reasonable time to investigate and address the reported issue before publicly disclosing information about it.

  2. Do not access, modify, download or interact with another person's private account or personal information without their explicit permission.

  3. Make a good-faith effort to avoid privacy violations, data loss, service disruption or degradation.

  4. Do not intentionally access, modify, delete, copy or disclose customer information or confidential business information.

  5. Do not exploit a vulnerability beyond what is reasonably necessary to demonstrate that the issue exists.

  6. Do not use security testing to commit fraud, financial theft, extortion or any other unlawful activity.

  7. Do not introduce malware, viruses, ransomware or other harmful software.

  8. Do not perform denial-of-service (DoS/DDoS) attacks or testing that could negatively affect the availability of our Website.

  9. Comply with applicable laws and regulations.

Reporting a Vulnerability

To help us investigate efficiently, please include as much relevant information as possible in your report, including:

  • A clear description of the vulnerability.

  • The affected page, feature or URL.

  • Steps required to reproduce the issue.

  • Screenshots or supporting evidence where appropriate.

  • The potential security impact.

  • Any relevant browser, operating system or device information.

  • Your contact information so we can respond if additional details are required.

Please send security reports to:

support@coastora.co.uk

Please use "Security Vulnerability Report" as the email subject where possible.

What You Should Not Do

When investigating a potential vulnerability, please do not:

  • Access another customer's account or personal information.

  • Download or retain customer information.

  • Modify or delete data belonging to Coastora or its customers.

  • Perform social engineering or phishing attacks.

  • Attempt to obtain employee or customer passwords.

  • Conduct physical security attacks.

  • Send spam or unsolicited communications.

  • Perform denial-of-service testing.

  • Install malware or malicious software.

  • Attempt to disrupt our Website, checkout or payment systems.

  • Publicly disclose a vulnerability before we have had reasonable time to investigate it.

If you accidentally access confidential or personal information while investigating an issue, stop testing and inform us in your report.

Our Response

When we receive a legitimate security report, we may:

  • Review and validate the reported vulnerability.

  • Contact you for additional information.

  • Investigate the potential impact.

  • Work with relevant service providers where necessary.

  • Take reasonable measures to correct confirmed vulnerabilities.

Response and resolution times will depend on the complexity, severity and potential impact of the reported issue.

Security Rewards

Coastora does not currently operate a guaranteed paid bug bounty programme.

Submitting a vulnerability report does not create an entitlement to payment, compensation or other reward.

If we choose to recognise a particularly helpful security report, any recognition or discretionary reward will be determined solely by Coastora and agreed separately.

Third-Party Services

Our Website may use third-party platforms, applications, payment providers and other services.

Security vulnerabilities that exist entirely within a third-party service may need to be reported directly to the relevant provider.

If you are unsure whether an issue relates to Coastora or a third-party service used on our Website, you may contact us and provide details of the issue.

Good-Faith Security Research

We appreciate responsible security research conducted in good faith and in accordance with this policy.

This policy does not provide permission to violate applicable laws, access information without authorisation, disrupt our Services or interfere with the rights or privacy of others.

Contact Us

For security-related enquiries or vulnerability reports, please contact:

Coastora

Address: 224 Milton St, Walsall WS1 4LW, United Kingdom
Telephone: +44 7449 721052
Email: support@coastora.co.uk
Website: coastora.co.uk