HM Land Registry · Vulnerability Disclosure

Hm Land Registry Vulnerability Disclosure

Vulnerability disclosure

HM Land Registry runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Real-EstateUnited KingdomLand RegistryOpen DataTitleConveyancingProperty RecordsPrice Paid DataLinked DataGeospatialGovernmentPropTech
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Contact
https://hackerone.com/44c348eb-e030-4273-b445-d4a2f6f83ba8/embedded_submissions/new
Contact
https://hackerone.com/3ad49ea1-a817-4a0e-87c5-9282e8538d49/embedded_submissions/new
Contact
https://www.gov.uk/contact/govuk

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-26'
method: searched
probe: true
source: https://www.gov.uk/guidance/report-a-vulnerability-on-an-hm-land-registry-service-or-system
summary: >-
  HM Land Registry publishes its own named vulnerability disclosure policy on
  GOV.UK, in addition to being covered by the GOV.UK platform security.txt and by
  the Use land and property data service's own security.txt. The policy explicitly
  endorses working with the security research community and covers all HMLR
  products and services, including third-party suppliers. There is no bug bounty:
  HMLR states plainly that it does not offer rewards, financial or otherwise.
policy:
- https://www.gov.uk/guidance/report-a-vulnerability-on-an-hm-land-registry-service-or-system
- https://www.gov.uk/help/report-vulnerability
contact:
- https://hackerone.com/44c348eb-e030-4273-b445-d4a2f6f83ba8/embedded_submissions/new
- https://hackerone.com/3ad49ea1-a817-4a0e-87c5-9282e8538d49/embedded_submissions/new
- https://www.gov.uk/contact/govuk
acknowledgments:
- https://vdp.cabinetoffice.gov.uk/thanks.txt
bug_bounty:
  offered: false
  detail: >-
    "We value those who take the time and effort to report security
    vulnerabilities according to this policy, however, we do not offer rewards
    (financial or otherwise) for vulnerability disclosures."
scope: >-
  Security vulnerabilities in HM Land Registry products and services. Applies to
  all users including HMLR staff, third-party suppliers and general users of
  HMLR internet-facing services.
response_targets:
  acknowledgement: within 5 working days of receipt
  substantive_response: usually within 10 working days
  triage_basis: impact, severity and exploit complexity
conditions:
- No public disclosure of a reported vulnerability without HMLR approval.
- No attempt to exploit a vulnerability to extract HM Land Registry data or records.
- >-
  The policy provides no indemnity for actions against the law, from HMLR or any
  third party.
escalation: >-
  Where it is unclear whether HMLR owns the affected service or IP address, the
  policy directs researchers to the National Cyber Security Centre (NCSC)
  vulnerability reporting route.
evidence:
- source: https://www.gov.uk/guidance/report-a-vulnerability-on-an-hm-land-registry-service-or-system
  kind: named HM Land Registry vulnerability disclosure policy
  verified: '2026-07-26'
- source: https://www.gov.uk/.well-known/security.txt
  kind: security.txt (live probe, RFC 9116)
  file: well-known/hm-land-registry-gov-uk-security.txt
  verified: '2026-07-26'
- source: https://use-land-property-data.service.gov.uk/.well-known/security.txt
  kind: security.txt (live probe, RFC 9116)
  file: well-known/hm-land-registry-use-land-property-data-security.txt
  verified: '2026-07-26'
  note: Expires 2025-06-03, which is in the past.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hm-land-registry-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.