GBPly
    Effective date: 20 April 2026

    Security Policy & Vulnerability Disclosure

    We welcome reports from the security community. This policy explains how to report vulnerabilities to 3Local Ltd, what we commit to in response, and the safe-harbor protections we offer for good-faith research.

    Coordinated disclosure

    Report a vulnerability privately and give us reasonable time to investigate and remediate before any public disclosure.

    Legal safe harbor

    Good-faith research within scope will not be pursued by 3Local Ltd, provided you follow this policy.

    Recognition

    We thank researchers who responsibly disclose valid issues with a credit on our public Acknowledgments page.

    Confidentiality

    We treat all reports as confidential and will not share your details without your permission.

    Found a security issue? Email support@gbpoptimiser.com with the subject Security Disclosure. Please do not file vulnerabilities through public bug reports or social media.

    1. Introduction

    3Local Ltd ("we", "us", "our") operates GBPly and related services. We take the security of our platform, our customers' data, and the wider internet community seriously.

    This Vulnerability Disclosure Policy explains how security researchers and members of the public can report potential security vulnerabilities to us, what they can expect from us in response, and the boundaries within which research is welcomed.

    We believe that close collaboration with the security community improves our security posture, and we appreciate the time and effort that researchers invest in helping us protect our users.

    2. Legal Notice

    This policy does not authorise actions that would violate applicable law. By participating, you agree to comply with all applicable laws, including the UK Computer Misuse Act 1990, the UK Data Protection Act 2018, the UK GDPR, and equivalent legislation in your jurisdiction.

    Where research is conducted in good faith and in accordance with this policy, 3Local Ltd will not initiate or support legal action against you in respect of accidental, good-faith violations of this policy. We cannot, however, authorise security testing on infrastructure owned or operated by third parties, and this policy does not override the terms of any third-party service.

    This policy is governed by the laws of England and Wales. Any dispute arising from or relating to this policy or any research activities conducted under it shall be subject to the exclusive jurisdiction of the courts of England and Wales, save that 3Local Ltd reserves the right to seek injunctive or equitable relief in any competent jurisdiction to protect its services, data, or users.

    3. Guidelines

    When testing, we ask that you act ethically and professionally. The following expectations and prohibitions are strict — breaching them voids the safe harbor offered in section 9.

    You must:

    • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data.
    • Use only your own accounts (or accounts you have explicit written permission to test). Create your own test workspace rather than interacting with production data belonging to other customers.
    • Stop testing and notify us immediately if you encounter user data, payment data, OAuth tokens, or authentication credentials belonging to other users.
    • Limit any proof-of-concept to the minimum required to demonstrate impact — typically a single redacted screenshot or HTTP response is sufficient.
    • Keep details of any vulnerability confidential between yourself and our security team until we have had a reasonable opportunity to remediate it.

    You must NOT:

    • Conduct denial-of-service, volumetric, or stress testing of any kind, including "low-and-slow" techniques, connection exhaustion, or resource starvation.
    • Run automated scanning that exceeds a low, human-equivalent rate of requests. Throttle to a maximum of 5 requests per second per endpoint, and cease immediately if asked.
    • Spam any forms, post submission, review, email, SMS, or webhook endpoints, even for testing purposes.
    • Modify, delete, encrypt, or corrupt any data belonging to us or any other user.
    • Use a vulnerability to access, copy, transfer, or retain customer data, personal data, business data, OAuth tokens, or credentials beyond the minimum required to demonstrate impact.
    • Pivot from a discovered vulnerability into other systems, establish persistence, or move laterally within our infrastructure.
    • Engage in social engineering of our staff, contractors, customers, or suppliers, or perform physical attacks against our offices or hardware.
    • Test third-party providers (Paddle, Supabase, Google, Resend, Twilio, etc.) — those are explicitly out of scope and operate their own disclosure programs.

    Any data inadvertently accessed during research must be handled in accordance with section 4.

    4. Data handling obligations

    If, in the course of good-faith research under this policy, you inadvertently access data that does not belong to you — including personal data, customer business data, OAuth tokens, credentials, or any other confidential information — the following obligations are non-negotiable:

    • Cease immediately. Stop the activity that produced the access as soon as you realise third-party data is involved.
    • Report promptly. Describe the nature and approximate volume of any data accessed in your initial report, but do not attach the data itself unless we explicitly request it.
    • Do not retain. You may not store, copy, transfer, sell, publish, or otherwise use any data accessed under this policy for any purpose other than the immediate report.
    • Securely destroy within 7 days. Any inadvertently obtained data must be securely destroyed within 7 days of our acknowledgment of your report, and you must confirm destruction in writing.
    • No public posting. Data accessed under this policy must never appear in blog posts, conference talks, social media, write-ups, or training datasets — whether identified or anonymised.

    Breach of these obligations voids the safe harbor in section 9 and may give rise to claims under the UK Data Protection Act 2018, UK GDPR, the EU GDPR, the California Consumer Privacy Act (CCPA), Canada's PIPEDA, and equivalent data protection laws worldwide.

    5. Scope

    The following assets are in scope for security research under this policy:

    • gbply.net and its subdomains operated by 3Local Ltd
    • mapsclientportal.com (white-label client portal infrastructure)
    • Public APIs and webhooks documented within the GBPly application

    The following are explicitly out of scope. Vulnerabilities in these systems should be reported directly to the relevant provider:

    • Paddle (billing, checkout, customer portal, tax handling)
    • Supabase (database, authentication, storage, edge function infrastructure)
    • Google APIs and Google Business Profile infrastructure
    • Resend (transactional email delivery)
    • Twilio and other SMS gateway providers
    • Customer-controlled email connectors (SMTP, SendGrid, Mailgun, Amazon SES, Postmark, Brevo) configured by individual workspaces
    • Customer-owned infrastructure, white-label custom domains, and content hosted by individual customers

    The following classes of finding are generally considered out of scope or low priority and are unlikely to be eligible for recognition unless combined with a demonstrable security impact:

    • Missing security headers without a working exploit
    • Missing best-practice TLS configuration without a demonstrable downgrade
    • Self-XSS, clickjacking on pages without sensitive actions, or CSRF on logout/non-state-changing endpoints
    • Reports from automated scanners without proof of impact
    • Rate limiting, brute-force, or denial-of-service issues
    • Email spoofing on domains without published SPF/DKIM/DMARC
    • Disclosure of public information or information that does not present a real risk
    • Vulnerabilities affecting only outdated or unpatched browsers and operating systems

    6. Reporting a vulnerability

    Please send vulnerability reports to support@gbpoptimiser.com with the subject line Security Disclosure.

    To help us triage and remediate quickly, please include:

    • A clear description of the vulnerability and its potential impact
    • Step-by-step reproduction instructions, including any URLs, HTTP requests, payloads, or scripts required
    • The date and time (with timezone) of your testing
    • Any screenshots, logs, or proof-of-concept files (please avoid including third-party or other users' data)
    • Your name or handle (if you wish to be credited on our Acknowledgments page) and preferred contact method

    Reports written in English are processed fastest, but we will do our best to respond to reports in other languages.

    7. Response timelines

    We aim to respond to security reports as follows:

    • Acknowledgment: within 3 business days of receipt
    • Initial assessment: within 10 business days, including a triage decision and severity rating
    • Remediation: dependent on severity and complexity, but typically within 30–90 days for valid issues
    • Resolution notice: we will let you know once a fix has been deployed and may invite you to verify it

    If a fix takes longer than expected, we will keep you informed of progress. Please continue to keep details of the issue confidential until we confirm that public disclosure is appropriate.

    8. Our commitment

    When you report a vulnerability in accordance with this policy, we commit to:

    • Respond promptly and treat your report with the seriousness it deserves
    • Work openly and collaboratively with you throughout triage and remediation
    • Not take or support legal action against you for good-faith research conducted within this policy
    • Credit you publicly on our Acknowledgments page (with your permission)
    • Notify you when the issue has been remediated

    9. Safe harbor

    3Local Ltd offers the following protections to researchers acting in good faith and within this policy:

    • Authorised access. We consider activities conducted consistent with this policy to constitute "authorised" conduct under the UK Computer Misuse Act 1990, the US Computer Fraud and Abuse Act, and equivalent computer-misuse legislation worldwide.
    • Terms of service waiver. We waive any restrictions in our Terms of Service and Acceptable Use Policy that would otherwise prohibit good-faith security research conducted within scope of this policy.
    • No anti-circumvention claims. We will not bring or support a DMCA (or equivalent) claim against you for circumvention of technical measures undertaken in good faith and within scope.
    • Third-party defence. If legal action is initiated by a third party against you for activities undertaken in accordance with this policy, we will take reasonable steps to make it known that your actions were conducted in compliance with this policy.

    Safe harbor is conditional. It is automatically voided — and we reserve all rights and remedies available to us — if you:

    • Conduct denial-of-service, volumetric, or stress testing of any kind;
    • Exfiltrate, retain, transfer, sell, or publicly disclose customer or user data beyond the minimum required to demonstrate impact;
    • Publicly disclose a vulnerability before we have had a reasonable opportunity to remediate it and have agreed disclosure timing with you;
    • Breach the data handling obligations in section 4;
    • Engage in social engineering, phishing, or physical attacks; or
    • Operate outside the scope set out in section 5, or against any third-party provider listed as out of scope.

    Good-faith determinations of compliance with this policy are made by 3Local Ltd, acting reasonably.

    10. Confidentiality

    We treat all vulnerability reports as confidential. We will not share your personal information with third parties without your consent, except where required by law or where necessary to remediate the issue (for example, if a vulnerability affects an upstream provider).

    We ask that you also keep the details of any vulnerability confidential between yourself and 3Local Ltd until we have had a reasonable opportunity to remediate it and have agreed any coordinated public disclosure timing with you.

    11. Limitations

    This policy applies only to security vulnerabilities. Bug reports, feature requests, and general support enquiries should be submitted via our in-app support channels or by emailing support@gbpoptimiser.com.

    We do not currently operate a paid bug bounty programme. Recognition is offered on a discretionary basis and is the only form of compensation provided under this policy.

    This policy does not grant permission to test third-party systems, even where they integrate with GBPly. Always check the relevant third party's own security policy first.

    This policy is a statement of intent, not a contract. It does not create any legal obligation on either party, does not form part of any agreement between you and 3Local Ltd, and does not constitute a waiver of any rights other than those expressly waived in section 9. Nothing in this policy limits 3Local Ltd's rights or remedies under applicable law in respect of activity that falls outside the scope, guidelines, or data handling obligations set out above.

    12. Recognition

    Researchers who responsibly disclose valid, in-scope vulnerabilities will, with their permission, be listed on our public Security Acknowledgments page.

    If you would prefer to remain anonymous, please tell us in your report and we will respect your wishes.

    13. Changes to this policy

    We may update this policy from time to time to reflect changes in our services, infrastructure, or legal environment. The latest version will always be available at this URL, and the effective date above will be updated accordingly.

    Material changes will be reflected in an updated effective date at the top of this page; researchers should review the current version before commencing any research activity.

    3Local Ltd is registered in England and Wales under company number 16598862. For questions about this policy, contact support@gbpoptimiser.com.

    This policy is published in machine-readable form at /.well-known/security.txt in accordance with RFC 9116.