Introduction
This vulnerability disclosure policy applies to any vulnerabilities you are considering reporting to us (the "Organisation"). We recommend reading this vulnerability disclosure policy fully before you report a vulnerability and always acting in compliance with it.
We value those who take the time and effort to report security vulnerabilities according to this policy. However, we do not offer monetary rewards for vulnerability disclosures.
Reporting
If you believe you have found a security vulnerability, please submit your report to us using the following email:
In your report please include details of:
What to expect
After you have submitted your report, we will respond to your report within 5 working days and aim to triage your report within 10 working days. We’ll also aim to keep you informed of our progress.
Priority for remediation is assessed by looking at the impact, severity and exploit complexity. Vulnerability reports might take some time to triage or address. You are welcome to enquire on the status but should avoid doing so more than once every 14 days. This allows our teams to focus on the remediation. When asking for updates please use the original email thread where possible so that all discussions are kept in one place.
We will notify you when the reported vulnerability is remediated, and you may be invited to confirm that the solution covers the vulnerability adequately.
Once your vulnerability has been resolved, we welcome requests to disclose your report. We’d like to unify guidance to affected users, so please do continue to coordinate public release with us.
Guidance
You must NOT:
You must:
Legalities
This policy is designed to be compatible with common vulnerability disclosure good practice. It does not give you permission to act in any manner that is inconsistent with the law, or which might cause the Organisation or partner organisations to be in breach of any legal obligations.
We have used Capital Stair Services for a couple of years now and gradually built up a larger portfolio of properties with them. We have always experienced a very good service from then team. All our developments are kept in good condition and we are very happy with the work carried out for us. We would be more than happy to recommend Capital Stair Services for any future jobs
Jill Hamilton | LAR Housing Trust
We get our stair cleaned every fortnight and the stair is regularly attended to, never failed to let us down. They kept us up to date during Covid-19, get our bills on time and lovely helpful people, very reliable, prompt and trustworthy. Service highly recommended.
Vivienne P | Resident, Edinburgh
This firm, previously known under the name ‘Edinburgh Stair Cleaning’, has been employed for over six years to clean weekly the tenement stair of three flats where I live. They have proved to be consistently reliable and their work completely satisfactory
Janet D | Resident, Edinburgh
Stair cleaning for a number of years. Done to a very high standard but if ever there has been a dip in performance this has been quickly addressed.
Alan S | Resident, Edinburgh
Delighted with the clean, effort and time the cleaner put in. Lovely guy. Thank you! And hope to organize a regular clean.
Zoe | Resident, Edinburgh