<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=6061692&amp;fmt=gif">
Skip to content

Search the Goodlord website

  • There are no suggestions because the search field is empty.

Goodlord Vulnerability Disclosure Policy

Last reviewed: July 2026

INTRODUCTION

Goodlord takes the security of our platform and our customers' data seriously. We welcome reports from security researchers and members of the public about potential vulnerabilities in our systems. This policy explains how to report a vulnerability to us, what we ask of you, and what you can expect from us in return.

REPORTING

If you believe you have found a security vulnerability in a Goodlord system, please email security@goodlord.com.

Please include, where possible:

  • The website, IP address, or page where the issue was found;
  • A clear description of the issue and the type of vulnerability;
  • The steps required to reproduce it (a proof of concept, screenshots, or a short recording all help).

Please report in English.

WHAT WE ASK OF YOU What (scope and conduct)

This policy applies to internet-facing Goodlord systems that we operate, including goodlord.com, app.goodlord.co, and our public-facing products and APIs. Services operated by third parties on our behalf, and any system not owned or controlled by Goodlord, are out of scope; please do not test them.

When investigating and reporting, please:

  • act in good faith to avoid privacy violations, degradation of service, and disruption to our systems or data;
  • only test against accounts you own or have explicit permission to test, and only interact with data that belongs to you;
  • not access, modify, delete, or exfiltrate other users' data, and not attempt to access or download personal data belonging to our customers, landlords, or tenants;
  • not carry out denial-of-service testing, social engineering, phishing, physical attacks, or spam;
  • give us a reasonable opportunity to investigate and remediate before disclosing an issue publicly. Unless we agree otherwise in writing, the default coordinated disclosure window is 90 days from the date we acknowledge receipt of your report.

If you inadvertently access personal data belonging to our customers, landlords, or tenants during your research, please stop immediately, do not view, copy, download, store, or share that data, delete any local copies, and tell us at once in your report. Goodlord processes personal data under UK GDPR, and handling such data responsibly is a condition of this policy.

The following are out of scope and we generally do not consider them actionable reports on their own: reports from automated scanners without a demonstrated, exploitable impact; missing HTTP security headers with no proven exploit; weak SSL/TLS cipher or configuration observations; clickjacking on pages with no sensitive state-changing action; rate-limiting, and best-practice or "informational" findings.

WHAT YOU CAN EXPECT FROM US

  • We will acknowledge your report and thank you for it.
  • We will pass it to the team responsible for the affected system and assess it.
  • Where appropriate, we will remediate the issue on a timeline that reflects its severity and our own priorities.
  • We do not commit to specific timelines and we do not share detailed internal findings or validation status.
  • We will not ask you to sign a non-disclosure agreement as a precondition of reporting.

HOW WE HANDLE YOUR DATA

When you submit a report, Goodlord will process your personal data (such as your name, email address, and any information you include in your report) as a data controller for the purpose of assessing and responding to your report. We will retain this information for as long as is necessary for that purpose and for our legitimate security records. For further information on how we handle personal data, please see our Privacy Policy at www.goodlord.com.

RECOGNITION & REWARDS 

Goodlord does not operate a paid bug bounty programme and does not offer financial compensation for vulnerability reports. For genuine, previously unknown, responsibly disclosed issues, we are happy to offer our thanks and, where appropriate and with your agreement, public acknowledgement.

SECURITY ACKNOWLEDGMENTS

Where we choose to recognise a report publicly, this is entirely at our discretion and may, for example, take the form of a public acknowledgement (such as a security acknowledgements or "Hall of Fame" page). The following conditions apply: acknowledgement is not guaranteed for any report; we only publish an acknowledgement after the issue has been resolved, and any description we include will be kept general so as not to expose sensitive detail; we will only publish your name or handle with your agreement (you are welcome to remain anonymous); and we do not acknowledge low-value, best-practice, or automated scanner reports that do not demonstrate a genuine, exploitable issue.

LEGAL

This policy is governed by the laws of England and Wales, and any disputes arising in connection with it are subject to the exclusive jurisdiction of the English courts.

This policy is provided to give security researchers clear guidance for reporting in good faith. It does not authorise any activity that is inconsistent with applicable law, and it does not grant permission to access data belonging to others. Actions taken in good faith and in accordance with this policy will be treated as authorised; we will not pursue action against researchers who comply with it.

For the purposes of this policy, 'good faith' means acting with the genuine intention of identifying and reporting a security vulnerability, not exploiting any vulnerability beyond what is strictly necessary to demonstrate its existence, and not using findings for personal gain or to harm Goodlord, its customers, landlords, or tenants.