Security
Keeping a small service careful
Security is treated as a launch condition, not a promise that any online service can be risk-free.
Pre-launch notice reviewed 3 September 2026.
How the pilot is designed
- The public site is static and has no application database or custom intake API.
- Personal submissions go directly to a dedicated Odoo Helpdesk candidate after its privacy and attachment gates pass.
- Device location is requested once only after a tap; there is no continuous or background tracking.
- Optional images are decoded, resized and re-encoded before upload; original metadata is not deliberately read or sent.
- Public caches exclude forms, tickets, portal pages, location, photographs and authenticated content.
Controls still required before launch
Odoo access isolation, attachments, deletion, Turnstile, mail, backup behavior and the browser widget must pass the recorded capability gate. Ian's internal account must use MFA and a separately protected recovery route. DNS, security headers and provider contracts must be evidenced.
If a critical privacy or attachment test fails, public intake stays off. The only permitted presentation or field fallbacks are the full-page Odoo form, manual location text and labelled native Description, and only where the capability gate explicitly allows each one.
Report a security concern
The intended contact is security@muirkirk.info. It must be tested before launch. Do not send passwords, MFA codes, private ticket links, resident records or working exploit code in the first message. Give a concise description, affected page and safe steps to reproduce.
If personal information may be exposed, say that clearly without including the information itself. Ian will use the breach process to contain, assess and record the event.
Safe reporting
Do not access another person's information, guess private ticket links, persist after demonstrating the issue, upload malware, use social engineering or disrupt the service. Ask for written permission before active security testing.
No bounty or safe-harbour programme is offered. Good-faith, minimal-impact reports are welcome, but this page does not authorise conduct that would otherwise be unlawful.
A security.txt contact file will be published only after the security mailbox and response ownership have been tested; an unmonitored address would create false reassurance.
Security incidents
Suspected incidents will be logged, contained and assessed. Where a personal data breach is likely to risk people's rights and freedoms, it must be reported to the ICO without undue delay and, where required, within 72 hours of awareness. People will be told without undue delay where the risk to them is high.
Updates will avoid exposing security details that could place residents or the service at further risk.
Not an emergency channel
This mailbox is not continuously monitored. Immediate danger, crime, safeguarding, gas, electrical, flooding, sewage and health emergencies belong with the official services listed on the report page.
For privacy requests rather than vulnerabilities, use the contact route described on the privacy page once it is live. See the privacy page.