Security reporting

Report vulnerabilities, suspicious activity, exposed data, or abuse.

Security reports route to security@cloudforgeacademy.co.uk. Use this page for responsible disclosure, platform security concerns, suspicious account behavior, data exposure, abuse, and cloud lab security issues.

Report types

Suspected account compromise or suspicious sign-in behavior

Possible vulnerability in the platform, API, billing, or lab workflow

Accidental exposure of learner, billing, or operational data

Abuse, phishing, impersonation, or harmful platform activity

Cloud lab security issue, cleanup failure, or unexpected resource exposure

Responsible disclosure or security research contact

Safe reporting

Do not include passwords, API keys, private keys, session cookies, or one-time codes.

You receive an acknowledgement with a reference ID after the form is accepted.

High-impact vulnerability and data-exposure reports are triaged within one UK business day.

Lower-risk security questions are reviewed within two UK business days.

Include the affected URL, approximate time, browser, account email, and safe reproduction notes.

For vulnerabilities, describe impact and evidence without accessing other users' data.

Security messages route to security@cloudforgeacademy.co.uk for urgent trust review.

Security form

Send a security report.

The form is pre-routed to security@cloudforgeacademy.co.uk. Share enough detail to understand impact, but do not include secrets or private credentials.

Email directly

Messages go to security@cloudforgeacademy.co.uk. Default contact address: contact@cloudforgeacademy.co.uk.