
Max
Pet
Security & Vulnerability Disclosure
Last updated: 17-07-2026
← Back to MaxPet
We take the security of MaxPet and the privacy of our users’ data seriously. If you
believe you have found a security vulnerability, we would genuinely like to hear from you.
How to report
Email [email protected] with a clear description, the steps to
reproduce, and — if you can — the potential impact. Please give us a reasonable
opportunity to investigate and fix an issue before disclosing it publicly.
Our commitment to you
- We will acknowledge your report, usually within a few days.
- We will keep you informed as we investigate and remediate.
- We support safe harbour: we will not pursue or support legal action
against anyone who reports in good faith and follows this policy.
Scope
This policy covers maxpet.co.uk and the MaxPet web app and API.
Please do
- Act in good faith and avoid privacy violations, data loss, or service disruption.
- Only test against your own account and data.
- Give us reasonable time to remediate before any public disclosure.
Please do not
- Run denial-of-service (DoS/DDoS), volumetric, or spam attacks.
- Access, modify, or delete data that is not yours.
- Use social engineering, phishing, or physical attacks against our team or users.
- Run automated scanning that degrades the service for others.
MaxPet is run by a small team and does not currently operate a paid
bug-bounty programme — but we are grateful for responsible reports and will happily
credit you (with your permission) once an issue is resolved.
Our machine-readable security contact is published at
/.well-known/security.txt (RFC 9116).