Identity-aware access
The application is protected by Cloudflare Access and restricted to approved identities. Application roles further limit viewer, operator and owner capabilities.
TRUST CENTRE
A private research workspace with layered access and operational controls.
The application is protected by Cloudflare Access and restricted to approved identities. Application roles further limit viewer, operator and owner capabilities.
Browser traffic is served over HTTPS. Security headers constrain framing, content types, browser capabilities and resource loading.
Security-relevant actions are audited, hosted configuration fails closed, and deployment data is held on persistent storage with recovery controls.
Please report suspected vulnerabilities privately to [email protected]. Include the affected URL, a concise description, reproduction steps and the likely impact. Security contact information is also published in the RFC 9116 security.txt file.
Use only accounts and data you are authorised to access. Do not use denial-of-service testing, automated high-volume scanning, social engineering, physical attacks or techniques that could impair the service or expose another person's data. Stop and report the issue if sensitive information is encountered. Do not publish a vulnerability before there has been a reasonable opportunity to investigate it.
Receipt and progress will be acknowledged when practicable, but no response or resolution time is guaranteed. This project does not currently operate a paid bug-bounty programme. Good-faith reports that follow this policy are welcomed.
This policy covers the public website and the protected Housebuilder Data Studio application on their official domains. Third-party platforms are governed by their own programmes. Availability information is provided on the service status page.
Last reviewed: 9 August 2026.