Bug Bounty

Report a vulnerability on a HOWDENINSURANCE.CO.UK domain or subdomain
A vulnerability is a technical issue with the HOWDENINSURANCE.CO.UK website which attackers or hackers could use to exploit the website and its users.
You will not be paid a reward for reporting a vulnerability (known as a ‘bug bounty’).

Guidelines for reporting a vulnerability

When you are investigating and reporting the vulnerability on a HOWDENINSURANCE.CO.UK domain or subdomain, you must not:

  • break the law
  • access unnecessary or excessive amounts of data
  • modify data
  • use high-intensity invasive or destructive scanning tools to find vulnerabilities
  • try a denial of service - for example overwhelming a service on HOWDENINSURANCE.CO.UK with a high volume of requests
  • disrupt HOWDENINSURANCE.CO.UK’s services or systems
  • tell other people about the vulnerability you have found
  • social engineer, phish or physically attack our staff or infrastructure
  • demand money to disclose a vulnerability


Reports must be submitted to it.security@howdeninsurance.co.uk

After you’ve reported the vulnerability

You’ll get confirmation that we have received your report within 5 working days. We’ll try to assess your report within 10 working days. We prioritise fixes by impact, severity and exploit complexity.