HM Land Registry · Vulnerability Disclosure

Hm Land Registry Vulnerability Disclosure

Vulnerability disclosure

HM Land Registry runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Real EstateUnited KingdomLand RegistryOpen DataTitleConveyancingProperty RecordsPrice Paid DataLinked DataGeospatialGovernmentPropTech
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Contact
https://hackerone.com/44c348eb-e030-4273-b445-d4a2f6f83ba8/embedded_submissions/new
Contact
https://hackerone.com/3ad49ea1-a817-4a0e-87c5-9282e8538d49/embedded_submissions/new
Contact
https://www.gov.uk/contact/govuk

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-26'
method: searched
probe: true
source: https://www.gov.uk/guidance/report-a-vulnerability-on-an-hm-land-registry-service-or-system
summary: >-
  HM Land Registry publishes its own named vulnerability disclosure policy on
  GOV.UK, in addition to being covered by the GOV.UK platform security.txt and by
  the Use land and property data service's own security.txt. The policy explicitly
  endorses working with the security research community and covers all HMLR
  products and services, including third-party suppliers. There is no bug bounty:
  HMLR states plainly that it does not offer rewards, financial or otherwise.
policy:
- https://www.gov.uk/guidance/report-a-vulnerability-on-an-hm-land-registry-service-or-system
- https://www.gov.uk/help/report-vulnerability
contact:
- https://hackerone.com/44c348eb-e030-4273-b445-d4a2f6f83ba8/embedded_submissions/new
- https://hackerone.com/3ad49ea1-a817-4a0e-87c5-9282e8538d49/embedded_submissions/new
- https://www.gov.uk/contact/govuk
acknowledgments:
- https://vdp.cabinetoffice.gov.uk/thanks.txt
bug_bounty:
  offered: false
  detail: >-
    "We value those who take the time and effort to report security
    vulnerabilities according to this policy, however, we do not offer rewards
    (financial or otherwise) for vulnerability disclosures."
scope: >-
  Security vulnerabilities in HM Land Registry products and services. Applies to
  all users including HMLR staff, third-party suppliers and general users of
  HMLR internet-facing services.
response_targets:
  acknowledgement: within 5 working days of receipt
  substantive_response: usually within 10 working days
  triage_basis: impact, severity and exploit complexity
conditions:
- No public disclosure of a reported vulnerability without HMLR approval.
- No attempt to exploit a vulnerability to extract HM Land Registry data or records.
- >-
  The policy provides no indemnity for actions against the law, from HMLR or any
  third party.
escalation: >-
  Where it is unclear whether HMLR owns the affected service or IP address, the
  policy directs researchers to the National Cyber Security Centre (NCSC)
  vulnerability reporting route.
evidence:
- source: https://www.gov.uk/guidance/report-a-vulnerability-on-an-hm-land-registry-service-or-system
  kind: named HM Land Registry vulnerability disclosure policy
  verified: '2026-07-26'
- source: https://www.gov.uk/.well-known/security.txt
  kind: security.txt (live probe, RFC 9116)
  file: well-known/hm-land-registry-gov-uk-security.txt
  verified: '2026-07-26'
- source: https://use-land-property-data.service.gov.uk/.well-known/security.txt
  kind: security.txt (live probe, RFC 9116)
  file: well-known/hm-land-registry-use-land-property-data-security.txt
  verified: '2026-07-26'
  note: Expires 2025-06-03, which is in the past.