← Back to home

Security

We take the security of our software and your data seriously. If you believe you have found a security vulnerability or wish to report a security incident, please let us know immediately.

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly by emailing us at:

paul@better-call-sam.co.uk

Please do not report security vulnerabilities through public GitHub issues or other public channels.

What to Include

  • 1A description of the vulnerability and its potential impact
  • 2Steps to reproduce the issue
  • 3Any relevant screenshots or proof of concept
  • 4Your contact details so we can follow up

Our Commitment

  • We will acknowledge your report within 2 business days
  • We will investigate and provide an initial assessment within 5 business days
  • We will keep you informed of progress towards a fix
  • We will not take legal action against researchers who report responsibly
  • If an incident affects personal data, we will report it to HMRC and the Information Commissioner's Office within 72 hours

Security Practices

  • All data is transmitted over encrypted connections (TLS)
  • OAuth tokens are encrypted at rest using AES-256-GCM
  • We send the fraud prevention headers HMRC requires for our type of application
  • No customer credentials are stored by our application
  • All data is stored on servers located in the United Kingdom

Last updated: July 2026