This policy creates a safe reporting route without authorising intrusive testing.
1. Scope and contact
Good-faith reports concerning RMCA-controlled websites and expressly listed services may be submitted to security@rmca.org.uk. The production page must list in-scope domains and exclude third-party systems not controlled by RMCA.
2. Authorised conduct
A researcher should use the minimum testing necessary to confirm a potential issue; avoid privacy impact, data access, persistence, denial of service, social engineering, physical testing, automated high-volume scanning, credential attacks or disruption; stop immediately if confidential, personal, case or participant evidence is encountered; and report promptly with reproducible detail.
3. Prohibited conduct
Public publishing, participant evidence, institutional access and complaint or case data must use separated access and security environments. Confidential evidence, bank details, KYB documents, personal complaint material and privileged information must not be uploaded to a public form or ordinary website content-management system.
Unauthorised access, probing, credential attacks, malicious automation, interference, malware, scraping contrary to published controls, or attempts to bypass purpose, role, consent, expiry or download restrictions are prohibited and may be reported to relevant providers or authorities.
This policy does not grant permission to violate law, third-party rights, contractual restrictions or another provider’s terms. It does not authorise public disclosure before RMCA has had a reasonable opportunity to investigate and remediate.
4. What RMCA will do
RMCA will aim to acknowledge a credible report, triage severity, protect reporter confidentiality where lawful, communicate proportionately and not pursue legal action solely for good-faith research that complies with this policy. This is not a reward or bounty promise.
5. Sensitive data
Do not include unnecessary personal data or live secrets in the initial message. Use an agreed secure transfer method for evidence. Complaint or case data is outside ordinary researcher scope.
6. Hall of thanks and disclosure
Recognition, coordinated disclosure timing and any public credit are discretionary and require mutual agreement. No reporter may use RMCA marks to imply employment, authorisation or endorsement.
Governing law and legal effect
Unless a separate contract states otherwise, these terms and non-contractual obligations arising from them are governed by the law of England and Wales. The courts of England and Wales have jurisdiction, subject to any mandatory rights, applicable consumer forum, arbitration or ADR rule that cannot lawfully be displaced.
Nothing in these terms overrides mandatory local law. If a provision is invalid or unenforceable, it is treated as modified to the minimum extent necessary, and the remaining provisions continue.
Changes and contact
RMCA may amend this document prospectively to reflect law, technology, programme scope, operating arrangements or risk. The current version, effective date and material change note should appear on the canonical page. Continued use after an effective change constitutes acceptance only to the extent permitted by law; material contractual changes follow the applicable contract.
Legal enquiries may be sent to legal@rmca.org.uk. Privacy enquiries: privacy@rmca.org.uk. Factual corrections and right-of-reply requests: corrections@rmca.org.uk. Security reports: security@rmca.org.uk. General service complaints: complaints@rmca.org.uk.
Responsible Markets Conduct Association — Company No. 17408187; incorporated in England and Wales; registered office: First Floor Office, 3 Hornton Place, London, W8 4LZ, United Kingdom.