Security
Last reviewed:
Effective from:
What this covers
This policy covers Lawnomic Ltd's public website, newsletter signup and confirmation, contact form and the delivery systems we operate for them. It does not describe a separate product application or authorise testing of our providers' infrastructure.
Our approach
We serve the website over HTTPS and use HTTP Strict Transport Security. We check form submissions using invisible Cloudflare Turnstile, a honeypot and server-side rate limits. A background check starts when you interact with a form. Newsletter subscriptions require email confirmation. Resend handles email delivery for the forms and stores newsletter contact records.
We restrict operational access, monitor dependencies and use server-side error reporting configured to minimise personal information. We avoid putting form contents, email addresses, credentials or confirmation links in routine logs. Our privacy policy explains providers, retention, analytics and browser storage.
We do not currently hold a SOC 2 attestation or ISO/IEC 27001 certification for this website. These practices do not guarantee that every vulnerability has been found or that interruptions cannot occur.
Report a vulnerability
Email security@lawnomic.com, monitored by Angus McLeod. Please send one report per issue, with the affected URL, a short description, safe reproduction steps, likely impact and your testing environment. Share only the minimum evidence needed. Do not put an unfixed finding, credentials or somebody else's information in a public issue or pull request.
We aim to acknowledge reports within five business days. Investigation and fix times depend on severity and complexity. We will coordinate with you about disclosure and useful updates. English is our preferred reporting language. We do not currently offer a bug bounty or monetary rewards.
Our machine-readable contact information is at security.txt.
Safe and useful testing
Limit testing to the public website and form behaviour we operate. Use your own test information and accounts. Avoid service disruption, repeated email delivery, destructive actions and access to other people's data. If you encounter such data, stop, do not retain unnecessary copies, and tell us privately.
Social engineering, physical attacks and denial-of-service testing against production are outside this policy. A missing header or speculative concern without a workable demonstration may not establish a vulnerability, but we will consider clear evidence of a practical impact.
We cannot give permission to test Fly.io, Cloudflare, Resend or another third party's systems. Their rules apply to those systems; report vulnerabilities in their services through their own channels.
Our commitment to researchers
We will not pursue legal action against researchers who make a good-faith effort to follow this policy, avoid privacy violations and service disruption, and give us a reasonable chance to remediate before public disclosure. This commitment applies to actions within Lawnomic's authority; it cannot bind another organisation.
Our website terms preserve this commitment. For an ordinary enquiry, use contact@lawnomic.com; for a privacy concern, use privacy@lawnomic.com.