Urban Intelligence takes the security of our systems and the data we hold seriously. We welcome reports from security researchers and members of the public who identify potential vulnerabilities in our services, and we are committed to working with you to resolve them.
Please email security@urbanintelligence.co.uk with enough detail for us to reproduce the issue: the affected system or URL, a description of the vulnerability, and the steps to reproduce it. Where possible, please include a proof of concept.
We will acknowledge your report within one working day, keep you informed as we investigate, and agree coordinated disclosure timelines with you on a per-report basis. We will let you know when the issue has been resolved.
We will not pursue or support legal action against researchers who act in good faith, comply with this policy, avoid privacy violations and service degradation, and do not access or modify data beyond what is necessary to demonstrate the vulnerability.
In scope: services operated by Urban Intelligence under urbanintelligence.co.uk and our PlaceMaker application. Out of scope: denial-of-service attacks, social engineering, physical attacks, and third-party services we do not operate.
Access, modify, or delete data that is not yours; degrade or disrupt our services; or publicly disclose a vulnerability before we have agreed a disclosure timeline with you.
This policy supports our ISO 27001 information security management system and operates alongside our Incident Management Policy. Last updated: 1 July 2026.