Security Policy

If you have discovered a security vulnerability on www.birtlessports.shop, we encourage you to notify Birtle's Sports immediately. We review all legitimate reports of vulnerabilities and work to address valid issues as quickly as possible.

Before submitting a report, please review this policy carefully, including our reporting principles, reward guidelines, and exclusions.

Fundamentals

If you follow the principles below when reporting a security issue to Birtle's Sports, we will not initiate legal action or an enforcement investigation against you in response to your report.

We ask that you:

  • Give us reasonable time to investigate and fix the issue before disclosing it publicly or sharing it with others.
  • Do not access or modify private accounts or data without the consent of the account owner.
  • Make a good faith effort to avoid privacy violations, service disruption, destruction of data, or degradation of our services.
  • Do not exploit any security issue you discover for any reason, including to demonstrate additional risk or access sensitive data.
  • Do not violate any applicable laws or regulations.

Vulnerability Reward Program

We value security researchers who help us protect our services by responsibly reporting vulnerabilities. Monetary rewards may be granted at the sole discretion of Birtle's Sports, based on the severity, impact, exploitability, and overall quality of the report.

To be considered for a reward, you must:

  • Follow the principles listed above.
  • Report a genuine security vulnerability in our services or infrastructure that creates a security or privacy risk.
  • Submit a clear and detailed report through our security contact process.
  • Avoid contacting employees directly about the issue.
  • Inform us immediately if, during your investigation, you unintentionally accessed confidential information or caused any privacy or service issue.

We investigate all valid reports. Due to the number of reports we may receive, response times can vary depending on risk and report quality.

We reserve the right to publish reports where appropriate.

Rewards

Reward amounts are based on the impact and seriousness of the vulnerability. We may update this program over time based on feedback and operational needs.

To qualify for a reward:

  • Your report must include enough detail for us to reproduce the issue.
  • If the same issue is reported more than once, only the first fully reproducible report will be eligible.
  • Multiple vulnerabilities caused by one underlying issue may be treated as a single report and receive one reward.
  • Reward decisions are based on factors including impact, exploitability, and report quality.

Reward Levels

Critical Severity (£200)

Vulnerabilities that may result in serious compromise, including:

  • Remote Code Execution
  • Vertical Authentication Bypass
  • SQL Injection exposing targeted data
  • Full account takeover

High Severity (£100)

Vulnerabilities that significantly affect the security of the platform, including:

  • Lateral Authentication Bypass
  • Disclosure of important internal company information
  • Cross-Site Scripting (XSS) affecting other users
  • Local File Inclusion

Medium Severity (£50)

Issues that affect multiple users and require little or no user interaction, including:

  • Common logic design flaws
  • Insecure object references

Low Severity

Issues that affect individual users and usually require user interaction or significant prerequisites, including:

  • Open Redirect
  • Reflected XSS
  • Low-sensitivity information disclosure

Contact Information

Birtle's Sports
Website: www.birtlessports.shop
Email: support@birtlessports.shop
Address: Central Buildings, 14 Corn Market, Penrith CA11 7HT