Wessex Region Wessex DPM Access Passport System
← Back to login

Security Contact

Found a vulnerability? Please report it responsibly.

Report security issues to support@nrapps.co.uk. This is a small, personally-maintained system (built and run by Oliver Viney) rather than a large security team — please allow a few days for a response, and follow up if you don't hear back.

What to include

Responsible disclosure

Good faith research

Security testing carried out in good faith, in line with the guidelines above, won't be treated as unauthorised or malicious. If in doubt about whether something is in scope, ask first at support@nrapps.co.uk.

What's already in place

For context, this system already applies: bcrypt-hashed passwords, signed httpOnly/secure session cookies, server-side role checks on every request (not just hidden UI), a login lockout after repeated failed attempts, TLS via Let's Encrypt, and standard security response headers (HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy). Reports that build on or work around these are exactly what this page is for.