Security
How we protect what you send us, and how to tell us about a weakness.
Reporting a vulnerability
Write to support@giftaidapi.co.uk with "Security" in the subject, describing what you found and how to reproduce it. We acknowledge every report and tell you what we did about it. Please do not test against other organisations' data, and give us time to fix a problem before you publish it.
Tools can find this route at /.well-known/security.txt.
How we work
- Every page is served over HTTPS, and nothing reaches the site except through its edge.
- Keys are shown once, when they are made. We keep only what we need to check them.
- The website sets only strictly necessary cookies, and loads nothing from another website.