TRUST CENTRE

Security

A private research workspace with layered access and operational controls.

Identity-aware access

The application is protected by Cloudflare Access and restricted to approved identities. Application roles further limit viewer, operator and owner capabilities.

Encrypted transport

Browser traffic is served over HTTPS. Security headers constrain framing, content types, browser capabilities and resource loading.

Operational safeguards

Security-relevant actions are audited, hosted configuration fails closed, and deployment data is held on persistent storage with recovery controls.

Report a security concern

Please report suspected vulnerabilities privately to [email protected]. Include the affected URL, a concise description, reproduction steps and the likely impact. Security contact information is also published in the RFC 9116 security.txt file.

Responsible testing

Use only accounts and data you are authorised to access. Do not use denial-of-service testing, automated high-volume scanning, social engineering, physical attacks or techniques that could impair the service or expose another person's data. Stop and report the issue if sensitive information is encountered. Do not publish a vulnerability before there has been a reasonable opportunity to investigate it.

What to expect

Receipt and progress will be acknowledged when practicable, but no response or resolution time is guaranteed. This project does not currently operate a paid bug-bounty programme. Good-faith reports that follow this policy are welcomed.

Scope and service information

This policy covers the public website and the protected Housebuilder Data Studio application on their official domains. Third-party platforms are governed by their own programmes. Availability information is provided on the service status page.

Last reviewed: 9 August 2026.