How to tell us about a security problem, and what happens next
If you believe you have found a security weakness in WAJD Academy or any WAJD service, please tell us. Write one email describing what you found, the exact address or request involved, and the steps to reproduce it.
security@wajd.co.uk
Please put the details in the body of the email as plain text. We do not open attachments, archives, or links to reports hosted on file sharing sites, so a report sent that way cannot be read or acted on.
This policy covers wajd.co.uk and every wajd.co.uk subdomain. It does not cover services run by other companies that we link to, such as exam board websites or our payment provider. Report issues in those to their owners.
Findings that come from an automated scanner with no demonstrated impact are not usually treated as security issues on their own. That includes missing headers on pages with no user data, version numbers reported by fingerprinting tools, and configuration advice with no route to exploit it.
WAJD is free to use and is funded to keep it that way. We do not operate a paid bug bounty. There is no reward, fee, invoice, retainer, or consultancy engagement attached to a report. Credit and our thanks are what we offer, and we offer them sincerely.
We run an automated review of every WAJD domain covering transport security, browser protection headers, certificate health, and the domain records that stop someone sending email in our name. We act on what it finds rather than waiting to be told.