Security
Last updated: 16 September 2026
Bakers Hub hosts websites and customer data for independent bakeries. If you have found a security problem, we want to hear about it — you do not need permission to report one, and we will not take action against you for reporting in good faith.
Reporting a vulnerability
Email [email protected]. Include enough detail for us to reproduce the issue: the affected URL or endpoint, the steps you took, and what you observed. Proof-of-concept code and screenshots help.
Machine-readable contact details are published at /.well-known/security.txt, per RFC 9116.
Scope
The Bakers Hub marketing site, the control plane at app.bakershub.co.uk, bakery storefronts on bakershub.uk subdomains, and custom domains hosted on the platform. Our infrastructure, our application code, and our handling of tenant and customer data are all in scope.
Out of scope
Content published by individual bakeries, third-party services we integrate with (report those to the vendor), missing security headers with no demonstrable impact, automated scanner output without a working proof of concept, and reports that require physical access or a compromised device.
Please do not run denial-of-service tests, send bulk or automated traffic, access or modify data belonging to a bakery or their customers, or degrade the service for anyone else. If you reach real customer data, stop and tell us.
What to expect
We aim to acknowledge your report within three working days and to give you an assessment and a rough remediation timeline within ten. Bakers Hub is a small operation, so we do not run a paid bug bounty — but we will keep you updated, and we will credit you when the fix ships if you would like us to.
Safe harbour
If you make a good-faith effort to follow this policy while researching, we will treat your work as authorised, will not pursue legal action, and will help clarify matters if a third party raises them. If you are unsure whether something is in scope, ask us first.
Acknowledgements
Our thanks to the researchers who have reported issues responsibly. Nobody is listed here yet — if that could be you, we would be glad to add your name.