tiney is an Ofsted-registered Childminder Agency. We recruit, register and support home-based childminders, and we run the apps and web services that connect them with the families who use them. That means we hold personal information about children, their families, and our childminders - so keeping our systems secure genuinely matters to us.
If you believe you've found a security vulnerability in any of our services, we'd like to hear about it, and we're grateful for the help.
How to report
Please email security@tiney.co with:
- The affected asset (domain, URL, IP address or service)
- A description of the vulnerability and its potential impact
- Steps to reproduce, including any proof-of-concept
Please report only your own findings, and give us a reasonable opportunity to investigate and fix the issue before disclosing it to anyone else.
Handling any data you come across. Please include your proof-of-concept inline in the body of your report (screenshots, short logs, request/response snippets) rather than as separate file attachments, and avoid capturing real personal data wherever you can. If, in the course of your research, you inadvertently access personal data belonging to a child, family or childminder, stop immediately, do not download, store or share it, tell us as soon as possible, and securely delete anything you obtained once you've reported it to us.
Safeguarding comes first
Because we work with young children, some vulnerabilities may carry a safeguarding dimension - for example anything that could expose a child's personal details, photos, location or daily records, or that could allow someone to identify or make contact with a child.
If you believe your finding has any safeguarding implication, please:
- Say so clearly and prominently at the top of your report, and treat it as urgent.
- Do not access, view, download, retain or share any data relating to a child. Stop as soon as you've confirmed the issue exists, and report it to us.
We treat any security incident with a potential impact on children as a major incident. It is escalated immediately through our incident-management process, with our Head of Safeguarding and Data Protection Officer involved, and we will notify the relevant authorities (such as Ofsted and the ICO) where required.
Scope
In scope - the public, internet-facing products and services we operate, including:
- Our childminder mobile app
- Our web app for families (searching, booking and paying for childcare)
- Other web and app services we host under
tiney.coand*.tiney.co
Out of scope:
- Denial-of-service (DoS/DDoS) attacks or volumetric/load testing
- Social engineering or phishing aimed at our staff, childminders or families, and physical attacks against people or premises
- Automated scanner output with no demonstrated, exploitable impact
- Reports about missing "best practice" headers or configuration with no proven security impact
- Third-party services we rely on but don't operate (for example our payment, messaging or infrastructure providers) - please report those to the provider directly
What to expect from us
- We'll acknowledge your report within 3 working days.
- We'll keep you updated as we investigate and work on a fix.
- We'll let you know once the issue is resolved.
- With your permission, we're happy to credit you once the issue is fixed.
Safe harbour
We consider security research and disclosure carried out in line with this policy to be authorised conduct. We will not pursue legal action against researchers who:
- Act in good faith and follow this policy;
- Never access, modify or delete data or accounts that aren't their own - and in particular any data relating to a child (see "Safeguarding comes first" above). We don't offer self-service test accounts, so if a test would require access to a real account or real data, stop and contact us first at security@tiney.co - we can arrange a safe way to test where it's warranted;
- Do not degrade, disrupt or damage our services; and
- Keep the details of the vulnerability confidential until we've had a reasonable time to fix it.
If a third party brings legal action against you in connection with research you carried out in good-faith compliance with this policy, we will take reasonable steps to make it known that your actions were authorised.
If you're unsure whether a specific action is authorised, email us at security@tiney.co and ask before proceeding.
Rewards
We don't currently operate a paid bug bounty programme. We review every good-faith report, act on genuine issues, and are glad to offer public credit (with your consent).





