Responsible Disclosure Programme
| Responsible Disclosure Programme | Version 1.0 |
| Owner | Chief Information Security Officer |
| Date last reviewed | 08/06/2026 |
Our Commitment
At Allica Bank, we take the security of our systems, customers, and data seriously.
We recognise and appreciate the role that security researchers play in identifying vulnerabilities and improving security across the internet. Our Security Team works collaboratively with researchers to investigate and remediate reported issues in a timely and responsible manner.
If you believe you have identified a security vulnerability in any of our systems or applications, we encourage you to report it to us.
When to Report
If you identify a potential vulnerability affecting Allica Bank systems, services, applications, or customers, please report it to us as soon as possible.
Scope
This policy applies to:
- Public-facing systems and services owned or operated by Allica Bank
- Domains and subdomains belonging to Allica Bank.
Out of scope:
- Missing Security Headers
- Version/Banner Disclosures
- Findings that do not demonstrate a clear, reproducible security impact or rely on unrealistic or unsupported assumptions, for example:
- Clickjacking on pages with no sensitive actions
- Self-XSS or user-controlled input that only affects user reporting
- Issues that rely on unrealistic user interaction
- Third-party systems not owned or controlled by Allica Bank
- Denial of Service (DoS/DDoS) testing
- Social engineering, phishing, or physical attacks against staff or customers
If you are unsure whether a system is in scope, please contact us before proceeding.
Safe Harbour
Allica Bank will not seek prosecution or legal action against researchers who:
- Act in good faith
- Comply with this policy
- Avoid causing harm to systems, services, or data
- Do not access or exfiltrate data beyond what is necessary to demonstrate the vulnerability
This safe harbour applies within the boundaries of applicable law, including the Computer Misuse Act 1990.
Guidelines for Testing
You may:
- Conduct reasonable and proportionate security testing
- Use automated tools where this does not negatively impact system availability or performance
- Identify and report vulnerabilities, including misconfigurations and exposed assets
You must not:
- Attempt to gain access to another user’s account or data
- Exfiltrate customer or sensitive internal data unless explicitly agreed in advance
- Modify system data or configurations
- Perform testing that could degrade service availability or integrity
- Conduct social engineering, phishing, or physical attacks
Testing should be limited to the minimum required to demonstrate the issue. In most cases, 2–3 examples are sufficient.
If validation requires more intrusive testing, please contact us in advance.
Handling of Sensitive Information
If you encounter sensitive information (e.g. API keys, credentials, personal data):
- Do not validate, exploit, or share the data
- Do not retain copies longer than necessary to report
- Provide sufficient detail to allow us to investigate
We may request confirmation that any such data has been securely deleted following acknowledgement.
Reporting a Vulnerability
To help us investigate effectively, please include:
- A clear description of the vulnerability
- The affected system, endpoint, or asset
- Steps to reproduce
- The potential impact
- Supporting evidence (e.g. screenshots or proof of concept where appropriate)
Reports that are low quality, lack reproducibility, or do not demonstrate a security impact may not be prioritised. If your report contains sensitive information, please use our PGP key.
Reports should be sent to: disclosure@allica.bank
Response and Triage
We aim to:
- Acknowledge receipt within 5 working days
- Triage and validate within 10 working days
If we are unable to meet these timelines, we will provide an update. Lack of response does not grant permission to exploit or publicly disclose vulnerabilities.
Disclosure
We support coordinated vulnerability disclosure.
- Please do not publicly disclose vulnerabilities until we have had a reasonable opportunity to investigate and remediate
- We will work with you to agree an appropriate disclosure timeline
- Where appropriate, we are happy to acknowledge researchers for their contribution
- All communications should go to disclosure@allica.bank
Publicly Exposed Credentials
If you discover exposed credentials (e.g. API keys, passwords):
- Do not attempt to validate or use them
- Report them to us with details of where and how they were discovered
- Use PGP encryption where sensitive data is included
Legal
This policy does not authorise any activity that would violate applicable laws or regulations, including:
- Computer Misuse Act 1990
- UK GDPR and Data Protection Act 2018
Additional Notes
- We may request further information or clarification, including proof-of-concept evidence where required.
- Do not contact other parts of the organisation (e.g. support channels, employees, or social media) regarding vulnerabilities, all communication should go through disclosure@allica.bank
PGP Key
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBGoNoDMBEACgEzh16sXY3cZegFNPrOZLhASaDCrZ7Py5fN6tNdB0Lsfpmnn5ol3aIGPnAvO/Fit68ahQdPc3hs125UBJfrv89A4Z73Nf6wJ/eWLFeIHhpxF89OUChWzO2h7Mz2CmaCdRn3i2UnSSTCCxGZf50r8ezgUvYqga6zfsktbNkR86fg/bED06N5WIZb7gRnTPKKqAHPJWg69C4il95n9sxl77RyVdhHiYZfIYJBh1kr8Fnyis1ftJmRT3NTt3WijiJDbcb8qB1DTxLZaoQ2FvbzkyPlgxu1SdZXb+0dRrDW6tDxJ9JV4gqHvylzWMXkzQDTgHEvlqhBTU+tIgm1LwRkBjtfg/fSg0nA9OKAiKnSLEEMJM5qY7+UDIgFICmzKybmWL4Zayu4HYDoDDa8OmfUTHv2lMcJT4mAtrfx6+SKF4Bt+Wc654IUH73BFOXp/kbrx1ZIp1kqj3ag6bkC2z8b3mWSeYAaqj9m96zQjaVbztrljt2ZltqGk0sC0a48MoFHw7Ea8j9DqGQVkeE6P8cmQ29F1a/clfqnlEf/dktYvGsutOZJaN6rPj7KyVC8KvMBPEcqTKkuLQwcO64TnrEhNXSULIvn7cGyLEaCGj9mOp3nbWycRFf3mzTmLwdo3T05fOUz+00ZNp47pwgGMfKg/JIdO999p1njbHg5CAvAhWPwARAQABtC9kaXNjbG9zdXJlQGFsbGljYS5iYW5rIDxkaXNjbG9zdXJlQGFsbGljYS5iYW5rPokCcwQTAQgAXRYhBBOJwGYCZ3KZkVXW6T8SyqxDSjoeBQJqDaAzGxSAAAAAAAQADm1hbnUyLDIuNSsxLjEyLDAsMwIbAwUJA8JnAAULCQgHAgIiAgYVCgkICwIEFgIDAQIeBwIXgAAKCRA/EsqsQ0o6Ho00D/9axGfCh0mbsADjJAd2smGE+FeVpLuiSIvTnYOwfwA+KD/YlCl217jFS6dVMpRv01tQ6Zuo3DiawUwPPO+Q+wxGCbeniMvWnt1UrSQ7cBXA2Gbhe/MI3pWiW+idPTOvmDryk3YahxiTfJMpUzXyCdHH/bN/jiBb2ZlvGIU8+b0LxoHNXcYSdboZm9KKwBjqAPrSpF/1OEjAhNRa5p0PWik3W8QKRj/jrGCc3lhj89+Dx452MTgF3IsKvbLaDHSiibpX82tc9fB/uZS+hmb5bOBxUpHTiyNRy+c9MpbmUsjitYsqzh2CbJBKYTL8IP4s/U8ahAHX7aR9MN6BuG/IQ6GNTwkzam7PwyQWhUptAeg9FmVsA/xy4HHiqSMx77TpVlPsrwEtUtm6C2bMwF4izly3k6zk2+CHTqYrmvH+GlDOT7BDvR7aBZU+CkcJ88yxnw+I1FC+N2Ipf92LP/gPKqwjc9d6Qg89j7UvPt3+aBjhary9XcvIwQdruC9Keu4rXDdWUll3e9smmTlHi2P/zFUyYzY2TcdUmcpVHrldK98WusS0/6B6QbdXVTQi8Dw4Xz8sCA693fxc0hy8pBiim1AQ3nB99IXnmKBTKYKq0YPYm85TycrVfEKA8d/7z+Cfs5fSCSVGiTRB8+qT4opoShoWNEdWUJ7AJg9Z+xBR7po83LkCDQRqDaAzARAAtEXt/Z0P/WF0zRdtLMC+T7dhviC8Rn00/i3RpK+IUGSS9p0n9VDVrFg/J+0ikJtx5CkVGxIZQd80OmzOHhoPaehsQ2lRYk1a2xkxPULEw5RGIu39D/0wjudU3GUrzZczNIW8+aprPfgeUVxQs5AQC8PfNK+4+63bwlZzzP12H7Hiu02X1o7gO+cCwJnsimZmVtL48dP7HFQxSv1SfS4HXwJYnA8iDmPVxv6CereTspUXiYfwWPJ2GCbCb9t8b3/8iNYw8AMt7A6U2jIXWm9OO77HAj9FKt8V039TCPsKmpmxYInVBd6l89XmcWkXZX1jdMOKrPsC5N3WIhnb5NRiBki+UFLRCf/amupKKo1NxKSLWL95gyGsotc47S4pHi1iPMobFAj6lzs+k91AViYhA5/ge8boebZgxXlBOYkcPT+b3BlKe6LkGBcH/cwY9+NKaa3OWx5li/GdAzniK04jE7VHr3BgKNKpjLg4K/i0dbrSm7TZhPOqqsmndjNy7cmHkWv//GgsqWodfoGVMziVlGVlTX8eWTu3vp6BJzFGp1deDlw8iLsEkbCC0OqKKWT2qjh3/vePsDjrJdyl3pI7QFyzH3WuED6EvzeNCACv8qdK+hOHGCI6BGpze+zI9EG0QSqeCV53Iznc6HC9DYt8z5jKO5mTzb2VgZsQCneQFdMAEQEAAYkCWAQYAQgAQhYhBBOJwGYCZ3KZkVXW6T8SyqxDSjoeBQJqDaAzGxSAAAAAAAQADm1hbnUyLDIuNSsxLjEyLDAsMwIbDAUJA8JnAAAKCRA/EsqsQ0o6HmvbD/9jT/PnAuWw8HYXnXdGV/MhHn0VG3RAYPatsBDhfX98dGpS3sDRJX12JZ/mtaZR9DEOJQ4RAYlJqF5bnO3WLDwOzqXZI8mG2D7tv6Ddb6ImtdSQ3840Y0KwJ2XFwoIJ1KdbY80P8f5VkYTuVDYgoejrVUWoipoy2xNWYhnLGUZw4EWt73Wwrwu5LidWLV8TGTVPf0YyiaSFb6m9Ry7a/nTm8R5GQ1XGLCKzWAVrrSurq0N4e02/haYSQtWXvlw8qKXXm4GPSMGf4OTkrz1UKCTGFZuSgzNo8lTeuGW+SFWKIzM8fNmvltwllQvTneeIK36izLnNELZkT9A+GBw1eY3+k13FmmrhyzL8ObDLR/AOxyUvDVeKq1NLmewSlJCgbvo/GKNPt8ZL4NBu9x2eTbkdMX+vbJNrrfKxCiFlWWIl+eRZbuRjP5sGCKRvMLYWb1mD/U+7CaiTlU2V6MlIE7urab7QD0cdaxs4Ptg7XCuZmqHca+G9EoviOC/w73Q8djZkgjgaw35rOyugnFxnElAXOE0rB7zGfE8xr7RAnKvTismTJgBgG4xeEeGulSCvj1DtYxshXE1uh2GtjWiA6tQVShgPxBKdRaorXl0uY8loxjuwgkYXZHkd7o75NASo3FKGI7vStQowwHAjcKFmzMZJ3HR80Jd0I+Bb8pAyhypyIQ===MABv
-----END PGP PUBLIC KEY BLOCK-----