Security Vulnerability Disclosure
Last updated: 27 July 2026
If you believe you've found a security vulnerability in Homaroo - the website, the booking flow, the Homaroo Engineer app, or the systems behind them - we want to hear about it. This page explains how to report it, what we ask of you while you look, and what you can expect from us in return.
How to report
Email [email protected] with as much of the following as you can:
- what you found and why you believe it's a vulnerability;
- the URL, screen or API endpoint affected;
- steps to reproduce it, ideally as a numbered list;
- a proof of concept if you have one (a screenshot, request/response, or short script) - whatever makes it fastest for us to confirm;
- a way to credit you (name, handle, or company) if you'd like one, and how you'd prefer we get back to you.
We don't currently offer a PGP key for encrypted email. If a report involves something you're not comfortable sending in plain text, say so in a short initial email and we'll agree a safer way to share the detail.
Scope
In scope: anything we run ourselves -
- the public website and booking flow at homaroo.co.uk;
- the Homaroo Engineer Android app;
- our server-side APIs and the accounts/data they expose.
Out of scope:
- vulnerabilities in third-party providers we use rather than run - Supabase, Stripe, Cloudflare, Google Firebase, postcodes.io, and our email and map providers. Please report those directly to the provider;
- denial-of-service or load testing of any kind;
- social engineering or phishing directed at our team, our customers, or our engineers;
- physical access to our offices, engineers, or equipment;
- spam, or automated scanning aggressive enough to degrade the service for real customers or engineers.
What we ask while you're testing
- test only against your own account and your own data. If you can see or change something that belongs to someone else, stop, don't go further with it, and tell us in your report;
- don't run automated scanners that could slow down or disrupt the platform for real customers or engineers;
- don't attempt denial-of-service testing;
- give us a reasonable chance to investigate and fix an issue before disclosing it publicly - we ask for 90 days, or sooner once we've confirmed a fix is live.
Our commitment to you
If you make a good-faith effort to follow this policy while researching a vulnerability, we will not pursue legal action against you for that research, and we won't report you to law enforcement over it. We'll work with you in good faith to understand and resolve what you've found.
What to expect from us
We aim to acknowledge a report within 3 working days, and to give you an initial assessment - confirmed, not reproducible, or more information needed - within 10 working days. Once we've confirmed an issue, we'll keep you updated as we work on it and let you know when a fix is live.
Recognition
We're a small team and don't currently run a paid bug bounty program. What we can offer is our thanks, and - if you'd like one and we've acted on your report - a public credit.
Contact
[email protected]. For anything unrelated to a security vulnerability, see our Privacy Policy for who we are and how to reach us generally.