← Back to home
Security
We take the security of our software and your data seriously. If you believe you have found a security vulnerability or wish to report a security incident, please let us know immediately.
Reporting a Vulnerability
If you discover a security vulnerability, please report it responsibly by emailing us at:
paul@better-call-sam.co.ukPlease do not report security vulnerabilities through public GitHub issues or other public channels.
What to Include
- 1A description of the vulnerability and its potential impact
- 2Steps to reproduce the issue
- 3Any relevant screenshots or proof of concept
- 4Your contact details so we can follow up
Our Commitment
- We will acknowledge your report within 2 business days
- We will investigate and provide an initial assessment within 5 business days
- We will keep you informed of progress towards a fix
- We will not take legal action against researchers who report responsibly
- If an incident affects personal data, we will report it to HMRC and the Information Commissioner's Office within 72 hours
Security Practices
- All data is transmitted over encrypted connections (TLS)
- OAuth tokens are encrypted at rest using AES-256-GCM
- We send the fraud prevention headers HMRC requires for our type of application
- No customer credentials are stored by our application
- All data is stored on servers located in the United Kingdom
Last updated: July 2026