Report a Security Issue
Vorigon takes the security of Vorigon.com and our customers’ data seriously. If you are a security researcher, a customer or simply someone who has noticed something wrong, we want to hear from you. This page explains how to report a security issue responsibly and what you can expect from us in return.
How to Report
Email info@vorigon.com with “Security Issue” in the subject line. For urgent issues you can also call +44 20 3996 1739 during business hours, Monday to Friday, 9:00 AM to 6:00 PM (GMT/BST).
Please include as much of the following as you can:
- The type of issue and where you found it — the page, URL or endpoint
- Clear, reproducible steps, including any payload, request or parameter involved
- What an attacker could actually achieve with it
- Screenshots, a short screen recording, or log excerpts
- The browser, device and time of the test, which helps us match it to our logs
- How you would like to be credited, if at all
We accept reports in English. Please do not post details publicly, on social media or in a forum before we have had a chance to fix the issue.
What We Will Do
| Stage | Our Commitment |
|---|---|
| Acknowledge your report | Within 2 business days |
| Initial assessment and severity rating | Within 5 business days |
| Progress updates | At least every 10 business days until resolved |
| Fix for critical issues | As a priority, typically within 30 days |
| Confirmation once resolved | We tell you when the fix is live and invite you to re-test |
We investigate every report we receive, including ones that turn out not to be vulnerabilities. We will always tell you our conclusion and why.
Responsible Testing Guidelines
If you are testing our site, please stay within these boundaries:
- Do not access, modify, download or delete data that is not your own. If you accidentally reach customer data, stop, do not save it, and tell us immediately.
- Do not run denial-of-service, load or stress tests, and do not use automated scanners that generate high request volumes.
- Do not use social engineering, phishing or physical intrusion against our staff, suppliers or premises.
- Do not place fraudulent orders or attempt to manipulate prices, discount codes or stock levels.
- Do not spam our forms or degrade the experience for other users.
- Use your own test account and your own data wherever possible.
- Give us reasonable time to fix the issue before disclosing it anywhere.
Safe Harbour
If you follow the guidelines above and report in good faith, Vorigon will not pursue or support legal action against you for your research, and we will treat your report as an authorised contribution to our security. If a third party brings action against you for activity that complied with this policy, we will make clear that your testing was authorised.
In Scope
- The vorigon.com website and its subdomains
- Our checkout and payment integration points
- Customer account areas and authentication
- Email systems operating under our domain, including SPF, DKIM and DMARC configuration
Issues we are particularly interested in: authentication or session flaws, broken access controls, injection vulnerabilities, cross-site scripting, cross-site request forgery, server-side request forgery, insecure direct object references, exposed credentials or configuration files, payment logic flaws, and anything that exposes customer or order data.
Out of Scope
- Vulnerabilities in third-party services we do not control, such as payment gateways or carrier tracking portals — please report those to the provider
- Reports generated purely by an automated scanner with no demonstrated impact
- Missing security headers, cookie flags or best-practice recommendations with no exploitable impact
- Rate-limiting or brute-force reports without a working proof of concept
- Self-XSS, clickjacking on pages with no sensitive action, and issues requiring an already-compromised device or browser
- Outdated browser or TLS version support
- Email spoofing of domains we do not own
- Denial of service, volumetric and resource exhaustion testing
- Physical security and social engineering
Recognition
Vorigon does not currently operate a paid bug bounty programme, so please do not expect a financial reward. What we do offer is a genuine thank-you: a written acknowledgement, a clear explanation of how we fixed the issue, and public credit on request once the fix is live.
If You Are a Customer
You do not need to be a researcher to report something. Please contact us straight away if you:
- Receive an email that appears to be from Vorigon but looks suspicious or asks for card details or a password
- Find a website, marketplace listing or social media account impersonating Vorigon — also see our Authorized Retailer & Authenticity page
- Think your Vorigon account has been accessed by someone else
- See another customer’s information displayed anywhere on our site
- Notice a charge on your statement you do not recognise — see our Billing Policy
We will never email or call you to ask for your full card number, your CVV or your account password. If someone does, it is not us.
How We Protect Your Data
Our security measures, retention periods and breach notification commitments are described in our Privacy Policy. Tracking and analytics scripts are covered in our Cookie Policy, and the rules for using our website are set out in our Terms of Service.
Related Pages
Contact Details
- Store Name: Vorigon
- Website: Vorigon.com
- Address: 23 Wharfside, Rosemont Road, Wembley, HA0, United Kingdom
- Phone: +44 20 3996 1739
- Email: info@vorigon.com
- Business Hours: Monday to Friday, 9:00 AM – 6:00 PM (GMT/BST). Closed on weekends and UK public holidays.
- Chat Support: Available 24/7 through the live chat window on Vorigon.com
You can also reach us through our Contact Us page. We reply to every email within 1 business day.