Security vulnerability reporting
Last updated: 1 October 2026
MoneyRepublic Ltd is a credit broker, not a lender. Registered in England and Wales under company number 12141408. Registered office: Lumiere House, Elstree Way, Borehamwood, WD6 1JH. Authorised and regulated by the Financial Conduct Authority, Firm Reference Number 1044827. Registered with the Information Commissioner's Office under registration number ZC001655.
MoneyRepublic takes the security of our website, systems and information seriously. We welcome responsible reports from security researchers and other users who believe they have identified a security vulnerability affecting MoneyRepublic.
1. Scope
This policy applies to security vulnerabilities affecting https://moneyrepublic.co.uk/ and systems or services that MoneyRepublic expressly identifies as being in scope. Third-party services, lender systems and other websites that we do not operate are outside scope unless we expressly state otherwise.
2. How to report a vulnerability
Please report suspected vulnerabilities to support@moneyrepublic.co.uk. Include enough information for us to understand and reproduce the issue where reasonably possible.
A useful report may include:
- the affected URL, page, endpoint or feature;
- a clear description of the issue and its potential impact;
- steps needed to reproduce the issue;
- screenshots, request/response examples or proof-of-concept material where safe and necessary;
- your contact details if you would like us to respond.
3. Responsible testing
If you carry out security research, please act in good faith and take reasonable steps to avoid harm. In particular, do not:
- access, copy, change, delete or retain personal information or confidential information beyond what is strictly necessary to demonstrate the issue;
- disrupt, degrade or deny access to our services, including through denial-of-service testing;
- use social engineering, phishing, physical intrusion or attacks against employees, customers, suppliers or other users;
- introduce malware or perform destructive testing;
- attempt to obtain funds, credentials or other property;
- continue testing after you have obtained sufficient evidence to demonstrate the vulnerability;
- publicly disclose an unresolved vulnerability before giving us a reasonable opportunity to investigate and address it.
4. Protecting data
If you encounter personal information, financial information, credentials or other confidential data while testing, stop accessing that data, do not download or share it, and tell us promptly. Please securely delete any copies created inadvertently once we confirm they are no longer needed for the report.
5. What you can expect from us
We will review reports made under this policy and may contact you for additional information. We will prioritise remediation according to the nature, severity and practical risk of the issue. We cannot promise a particular response or remediation time, and we may not be able to provide detailed information about internal systems or investigations.
Where a report concerns a third-party service or finance provider, we may need to refer the issue to that organisation or ask you to report it directly to them.
6. Good-faith research
This policy is intended to support responsible, good-faith security research. It does not authorise activity that is unlawful, causes harm, breaches the rights of others, or goes beyond what is reasonably necessary to identify and report a vulnerability. If you are uncertain whether a proposed test is appropriate, contact us before proceeding.
7. No rewards or compensation
Unless we expressly agree otherwise in writing, MoneyRepublic does not operate a bug-bounty programme and does not offer payment, rewards or compensation for vulnerability reports.
8. Public disclosure
Please do not publish or otherwise disclose details of a vulnerability until we have confirmed that it has been resolved or we have agreed a disclosure approach with you. Any coordinated disclosure should avoid exposing personal information, confidential information, credentials or details that would create unnecessary security risk.
9. Changes to this policy
We may update this Responsible Disclosure Policy from time to time. The latest version will be published on our website and will show the date it was last updated.
10. Contact
Security reports: support@moneyrepublic.co.uk General telephone: 0800 000 0000 MoneyRepublic Lumiere House, Elstree Way, Borehamwood, WD6 1JH
