Report a suspected vulnerability privately.
Responsible reports help protect visitors and the business. Please avoid publishing technical details before Dovy Studio has had a reasonable opportunity to investigate.
How to report
Email dovysstudio@gmail.com with the subject “Private security report”. Include the affected page or service, a clear description, steps to reproduce, the date and time observed, and the potential impact. Screenshots or a minimal proof of concept may be included if they do not contain unnecessary personal information.
Responsible testing
Please do not access, change, retain or disclose another person's information; disrupt availability; send high volume traffic; use destructive testing; attempt social engineering; or go beyond what is necessary to demonstrate the issue. Stop if testing could cause harm and report what you found.
What happens next
Dovy Studio will review genuine reports and may ask for clarification. No guaranteed response time, reward or bug bounty is offered. Where practical, Dovy Studio will keep the reporter informed and ask that vulnerability details remain private until a reasonable remediation period has passed.
Scope
This route is for suspected vulnerabilities directly affecting dovystudio.co.uk or its published contact flow. Problems in an unrelated third party service should normally be reported to that provider. General privacy concerns should use the complaint route in the privacy notice.
How the public website is protected
The site is built from static files and has no public account system or site database. A restrictive content security policy, transport security, clickjacking protection, content type protection, same origin isolation headers and limited browser permissions reduce common browser attack paths. The contact form posts to an external form processor, and card details are handled only by the agreed payment provider.
Traffic and availability
The release is prepared for Cloudflare Pages, where static files can be served from the edge and managed denial of service protection is available at the network. Firewall, bot, rate limit and emergency challenge controls remain deployment settings. They must be enabled, monitored and adjusted by the site owner without blocking legitimate visitors.
No guarantee of perfect security
Reasonable safeguards are used, but no public website or connected service can be guaranteed completely secure or always available. This page describes the public protections and reporting process without claiming that vulnerabilities, breaches or outages cannot occur.