Responsible Disclosure Policy
Contact: security@queenswaychemist.co.uk | Target SLA: 48-Hour Response
Queensway Chemist welcomes security researchers and the public helping us maintain the highest safety and privacy standards for our digital presence. If you discover an issue or vulnerability, we invite you to report it to us in accordance with this Responsible Disclosure Policy.
1. Safe Harbour Commitment
If you conduct vulnerability research and report in good faith pursuant to this policy, Queensway Chemist will:
- Consider your activities authorised and compliant with the Computer Misuse Act 1990.
- Not initiate or pursue civil or criminal legal action against you.
- Work collaboratively with you to understand, reproduce, and remediate the issue promptly.
2. Ground Rules for Testing
To qualify for safe harbour protection, you must adhere to the following:
- Do No Harm: Do not compromise patient safety or disrupt our pharmacy dispensing operations.
- Privacy First: Stop testing immediately if you encounter personal or clinical information. Do not download, view, retain, or share other people's data.
- No Denial of Service: Do not execute volume-based attacks (DoS/DDoS) or brute-force form flooding.
- No Physical or Social Engineering: Do not attempt physical attacks on our premises at 14 Manchester Road or social engineering/phishing of pharmacy staff.
- Confidentiality: Keep vulnerability details confidential until we have verified and remediated the issue.
3. In-Scope and Out-of-Scope Assets
In Scope: Public web pages and client-side code under *.queenswaychemist.co.uk.
Strictly Out of Scope:
- NHS England core infrastructure, Electronic Prescription Service (EPS), and NHS Spine systems.
- Third-party scheduling platforms (Cal.com) — please report directly to their respective security teams.
- Content Delivery Networks or domain registrar systems.
4. How to Submit a Report
Please email your findings to security@queenswaychemist.co.uk including:
- Description and location (URL or endpoint) of the potential vulnerability.
- Step-by-step reproduction instructions and minimal proof-of-concept (PoC).
- Assessment of the potential risk or clinical/privacy impact.
5. What to Expect from Us
We will acknowledge receipt of your submission within 48 hours, validate the findings with our technical team, provide regular progress updates, and confirm when the patch is safely deployed.