Draft — pending final solicitor review. Maintained by VenueCore Ltd. Not legal advice.
Security & Vulnerability Disclosure
Version 2026-06-A · Researcher contact and platform security posture. Companion document to Incident Response.
1. Reporting
Email security@venuecore.solutions with a clear description, reproduction steps, affected URL/endpoint, and (where safe) a proof of concept. We acknowledge within 2 business days, triage within 5, and aim to remediate critical issues within 30 days.
2. Safe harbour
We will not pursue civil or criminal action against good-faith researchers who: (a) follow this policy, (b) avoid privacy violations, service degradation and data destruction, (c) give us reasonable time to remediate before public disclosure, and (d) do not exploit findings beyond what's necessary to demonstrate impact. This safe harbour does not waive third-party rights (e.g. Stripe, Cloudflare, Lovable Cloud).
3. In scope
venuecore.solutions and all subdomains; the POS PWA; the customer, admin and partner portals; public API endpoints under
/api/public/*; and any official VenueCore mobile build.4. Out of scope
Findings that require physical access to a venue's premises; social-engineering of staff or end-guests; denial-of-service; rate-limit / brute-force findings without a working bypass; third-party infrastructure operated by Cloudflare, Stripe, Lovable Cloud or AI providers (please report directly to them); and any finding that requires the researcher to violate UK law.
5. Recognition
We maintain a public hall-of-fame for researchers who responsibly disclose validated findings. We do not currently pay cash bounties but may offer one-off rewards at our discretion.
6. Penetration testing & assurance
Internal continuous security review on every release; automated SAST + dependency scanning in CI; quarterly third-party configuration review of Cloudflare, payment, and database boundaries. An annual independent penetration test is performed by a CREST-accredited firm; the executive summary is available under NDA to enterprise customers on request via security@venuecore.solutions.
7. Cryptography & PCI
TLS 1.2+ in transit (modern ciphers only). AES-256 at rest for database and storage (managed). Integrated card processing is handled by Stripe — VenueCore never sees the PAN. The external-PDQ path captures only Luhn-validated last-4, scheme, and auth code; no full PAN, CVV, expiry, or track data is ever accepted or transmitted. See MSA §11 for the full PCI position.
8. security.txt
Machine-readable disclosure metadata is published at /.well-known/security.txt.