generated: '2026-07-25' method: searched probe: true source: https://www.bymiles.co.uk/security-vulnerability-reporting-policy policy: - https://www.bymiles.co.uk/security-vulnerability-reporting-policy contact: - vulnerability@bymiles.co.uk encryption: - https://www.bymiles.co.uk/static/bymilesvulnerabilitypgp.asc program: name: By Miles security vulnerability reporting policy type: responsible-disclosure bug_bounty_platform: none platform_note: >- By Miles runs its own direct-to-email disclosure programme. No HackerOne, Bugcrowd or Intigriti listing was found. policy_updated: '2020-10-15' scope: >- By Miles systems across all supported platforms. Researchers are asked to name the affected By Miles domain/subdomain and the affected URL/endpoint/API in each report. response_target_days: 5 rewards: swag: true hall_of_fame: true cash: discretionary cash_note: >- For particularly severe vulnerabilities the By Miles security committee may make a discretionary cash award. No published bounty table. hall_of_fame_named: - Sohail Ahmed - Aman Mahendra - Muhammad Asjad Sheikh - Bulletproof Security - Cyberis Limited report_requirements: - Full name - Email address - Company name (if applicable) - Bug description - Steps to reproduce the bug - Affected By Miles domain/subdomain - Affected URL/endpoint/API - PGP public key (encrypted reports are prioritised) rules: - Do not violate customer privacy, destroy or modify data, or disrupt or degrade services. - Do not target physical security measures, or use social engineering, spam or DDoS. - On finding a severe vulnerability that allows system access, stop and do not proceed further. - Exploiting or mis-using a vulnerability for personal or third-party benefit disqualifies the report. - Allow reasonable time to correct the issue before any public disclosure. security_txt: published: false note: >- No RFC 9116 /.well-known/security.txt is served on www.bymiles.co.uk (404) or api.bymiles.co.uk (403), even though a full disclosure policy, a dedicated reporting mailbox and a PGP key are all published as HTML/static assets. Publishing a security.txt pointing at the existing policy would be a one-line win for this provider. evidence: - source: https://www.bymiles.co.uk/security-vulnerability-reporting-policy kind: disclosure-policy status: 200 - source: https://www.bymiles.co.uk/information-security kind: isms-policy-pdf status: 200 note: >- ISMS policy (v2.1, 20 May 2026, signed by CEO Maddy Howlett) explicitly names the vulnerability reporting policy URL as a published commitment. - source: https://www.bymiles.co.uk/static/bymilesvulnerabilitypgp.asc kind: pgp-public-key status: 200