We welcome reports from security researchers. If you believe you have found a vulnerability on leadchangegroup.com, please tell us privately so we can fix it before it is disclosed.

How to report a vulnerability

Write to hello@leadchangegroup.com with:

  • the affected URL or endpoint, and what an attacker could do;
  • the steps to reproduce it, with any request, payload or screenshot that helps;
  • how you would like to be credited, if at all.

Our contact details are also published in our security.txt file. Please give us reasonable time to investigate and fix the issue before you share it with anyone else.

Scope

In scope: leadchangegroup.com and the forms and APIs it serves, such as the matching form and the correction request form.

Out of scope: services we use but do not operate, such as Cloudflare and Cloudflare Turnstile, and the websites of the software vendors we cover. Please report issues in those services to their owners.

Please avoid

  • Accessing, changing or deleting data that is not yours, beyond the minimum needed to show the issue.
  • Submitting forms with other people's personal details, or flooding the forms with requests.
  • Denial-of-service tests, spam, social engineering or physical attacks.
  • Automated scanning that sends large volumes of requests.

We do not run a paid bug bounty program.

How we protect the site

  • Encrypted connections only. The site is served over HTTPS with TLS 1.2 or later, and HTTP Strict Transport Security tells browsers never to connect without encryption.
  • Strict browser policies. Every page carries a Content Security Policy that only allows our own scripts and the Cloudflare services we use, and the site cannot be embedded in other websites.
  • Least-privilege data access. The part of the system that serves pages can only read published content. Form submissions are written through a separate role that cannot read them back, and the system that builds our pages has no access to them.
  • Bot protection. Forms are protected by Cloudflare Turnstile, rate limits and server-side validation.

How we handle personal data is described in our privacy notice.