Urban Assist

Your trusted platform for home services across the UK. We connect you with verified professionals for cleaning, repairs, installations, and more.

Company

  • About Us
  • Terms of Use
  • Privacy Notice

Policies

  • Cookies Policy
  • Cookie Reference
  • Refund Policy
  • Cancellation Policy
  • Service Fulfilment
  • Disclaimer
  • Accessibility
  • DPA
  • Acceptable Use
  • Security
  • Responsible Disclosure
  • Community guidelines

Services

  • Home cleaning
  • Plumbing
  • Electrical
  • Gardening
  • All services

For customers

  • Browse all services
  • Reviews
  • Refer a friend
  • Help Centre

For providers

  • Join as a Pro
  • Partner Login
Urban Assist

© 2026 Urban Assist Services Ltd. Registered in England & Wales. All rights reserved.

128 City Road, London EC1V 2NX · Company No. 14892337

Urban AssistBack to home

Last updated 7 September 2026

Responsible disclosure

We would rather hear from you than learn the hard way. If you have found a security vulnerability in Urban Assist, this page explains how to tell us privately, what we promise in return, and how coordinated disclosure works.

Scope

This policy covers all web applications, services, and API endpoints operated under urbanassist.co.uk. Out-of-scope: physical attacks, social-engineering of staff, and denial-of-service testing against production.

If you are unsure whether something is in scope, include it and we will triage it.

How to report

Email info@urbanassist.co.uk with:

  • A short description of the vulnerability and its potential impact.
  • Steps to reproduce, including URLs, account type, and any proof-of-concept code.
  • The date and time you observed the issue.
  • Your contact details and, if you want credit, how you would like to be named.

Do not report vulnerabilities via in-app chat. Send all reports directly to info@urbanassist.co.uk.

What we ask of you

  • Do not access, modify, or exfiltrate data that is not your own.
  • Do not disrupt the service or degrade performance for others.
  • Do not use the vulnerability beyond what is needed to demonstrate it.
  • Keep the issue private until we have had a chance to fix it — see coordinated disclosure below.
  • Comply with the law. This policy does not authorise unlawful activity.

What we promise — safe harbour

If you act in good faith and follow this policy, we will:

  • Not pursue civil action or report you to law enforcement for the report itself.
  • Treat your report as confidential and share it only with those who need to know to fix the issue.
  • Acknowledge receipt and give you a timeline for a fix or a request for more detail. We reply within one working day.
  • Credit you in an advisory if you would like to be named (otherwise we keep you anonymous).

Our safe harbour applies only to the report. It does not cover subsequent misuse, data theft, or any other breach of the law.

What to expect after you report

  1. Acknowledgement — we confirm we received your report and whether we need more detail. We reply within one working day.
  2. Triage — we assess severity and assign an owner, typically within 5 business days.
  3. Fix — we schedule a fix proportionate to severity. Critical issues affecting payments or personal data are treated as incidents under our Security policy.
  4. Closure — we tell you when the fix is live and, if appropriate, ask you to verify it.

We aim to resolve most reports within 30 days. Where a fix needs longer, we will keep you updated.

Coordinated disclosure

Give us a reasonable window to fix the issue before you disclose it publicly — typically 30 days from acknowledgement, longer for complex fixes we are actively working on. We will coordinate the advisory timing with you. If we do not respond, you may disclose responsibly after that window, without disclosing exploit details that would put users at risk.

Out-of-scope and misuse

Reports of missing security headers, clickjacking on non-sensitive pages, or rate-limit observations without a demonstrated impact are low priority and may be closed as “acknowledged — not planned”. False positives generated by automated scanners without manual verification are also out of scope.

Declaring participation in this programme does not excuse abuse, extortion, or any attempt to leverage a finding for gain. We track and may block automated abuse of this channel.

Contact and alternative

Primary: info@urbanassist.co.uk. If you need an encrypted channel, ask us for a PGP key and we will provide one.

Questions about how we handle security overall? See our Security policy and Privacy notice.