Effective Date: 26th August 2026
1. Introduction
Atto Limited, trading as Atto Partners ("we", "us", or "our"), takes the security of our own systems and of the systems we build and operate for our clients seriously. If you believe you have found a security vulnerability in one of them, we would like to hear from you, and this page explains how to tell us and what happens next.
2. Scope
This policy covers:
- the website www.attopartners.com
- applications and infrastructure operated by Atto Limited
- applications we have built and operate on behalf of our clients
Where a report concerns a system we operate for a client, we pass it to that client without delay and handle it under our incident response procedure.
3. How to Report
Email [email protected]. Please include:
- the address or name of the system affected
- a description of the vulnerability and its likely impact
- the steps needed to reproduce it
- how we can contact you if we have questions or want to keep you informed
Please include only as much detail as is needed to demonstrate the problem, and do not send us personal data or confidential material that you may have encountered.
4. What We Ask of You
- Act in good faith and within this policy.
- Do not access, modify, copy or delete data beyond what is necessary to demonstrate the vulnerability.
- Do not disrupt or degrade our services or those of our clients.
- Do not use social engineering, phishing, physical intrusion or denial of service.
- Do not share the vulnerability with others or make it public until we have fixed it and agreed with you how and when it is disclosed.
- Give us a reasonable time to investigate and fix the problem before any disclosure.
5. What We Will Do
- Acknowledge your report within one working day.
- Investigate it, assess its severity and keep you informed of our progress.
- Pass any report affecting a client system to that client without delay.
- Fix confirmed vulnerabilities within a timescale proportionate to their severity.
- Credit you for the finding if you would like us to, once it has been fixed.
We do not operate a bug bounty programme and do not offer payment for reports.
6. Good Faith
We will not pursue legal action against anyone who discovers and reports a vulnerability in good faith and in accordance with this policy.
7. Out of Scope
- Third-party services and platforms that we do not control
- Findings from automated scanners without evidence that they can be exploited
- Missing security headers or configuration best practice with no demonstrated impact
- Denial of service, resource exhaustion or brute force attacks
- Social engineering or phishing of our staff or clients
- Physical attacks on our premises or equipment
8. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with a new effective date. A machine-readable summary is published at /.well-known/security.txt.
9. Contact Us
Atto Limited25 Donegall Street, Belfast, Northern Ireland, BT1 2FF
Security: [email protected]
General: [email protected]