Vulnerability disclosure policy
Digital Skills Assessment holds learner data on behalf of colleges, training providers and employers, and we take the security of that data seriously. If you believe you have found a security vulnerability in www.digitalskillsassessment.co.uk or our public API, we want to hear from you.
How to report
Email admin@digitalskillsassessment.co.uk with the word "SECURITY" in the subject line. Please include:
- a description of the issue and where you found it (URL, endpoint or feature)
- steps to reproduce it, or a proof of concept
- what you believe the impact is
- how we can contact you for follow-up
Our machine-readable contact details are published at /.well-known/security.txt.
What to expect from us
- We will acknowledge your report within 3 working days.
- We will investigate, keep you informed of progress, and tell you when the issue is resolved.
- We will not take legal action against you for security research carried out in good faith and within the scope below.
- With your permission, we are happy to credit you once the issue is fixed.
Scope and good-faith research
When researching, please:
- do not access, modify or download data that is not your own — if you encounter learner or customer data, stop and report immediately
- do not run denial-of-service, spam or automated high-volume scanning tools
- do not use social engineering, phishing or physical attacks against our staff or customers
- only test against accounts you own or have created for the purpose
- give us a reasonable opportunity to fix the issue before disclosing it publicly
We do not currently operate a paid bug bounty programme. Reports made in line with this policy are always welcome and appreciated.
Last updated: 4 August 2026