Last Updated: 15 September 2026

1. Platform Security Measures

We maintain high standards of security across our web presence and client workflows:

  • Transport Layer Security (HTTPS): All web traffic is encrypted in transit using industry-standard TLS protocols with HSTS preloading.
  • Zero Financial Credential Storage: We never request, process, or store credit card numbers, online banking passwords, or account PINs on our website. All payout rails (Wise, PayPal, Tide) are configured directly by clients on official third-party portals.
  • Form Abuse & Anti-Spam Protections: Our consultation forms incorporate multi-layered defences including Google reCAPTCHA v3 bot verification, honeypot traps, and client-side submission rate limiting to prevent denial-of-service and inbox flooding.
  • Input Sanitization: All form inputs are strictly validated against restrictive length and regex patterns to mitigate cross-site scripting (XSS) and injection attacks.
  • Third-Party Processor Vetting: Outbound lead delivery partners (FormSubmit.co, EmailJS) are vetted for compliance with UK and international data protection standards.

2. Vulnerability Disclosure Policy

We welcome contributions from cybersecurity professionals and ethical researchers. If you identify a security vulnerability within our web assets, we encourage you to report it to us responsibly.

Scope

The scope includes the web application hosted at muhammadtahirzamanltd.com and related public-facing subdomains.

Safe Harbor & Guidelines

We commit not to pursue legal action against researchers who adhere to the following principles:

  • Act in good faith to avoid privacy violations, data destruction, and service interruption.
  • Do not execute Denial of Service (DoS/DDoS) attacks or automated brute-force scanning that degrades website availability.
  • Do not access, download, or alter client data or communications.
  • Provide a reasonable timeframe (standard 90-day disclosure period) to allow our team to investigate and remediate findings before public release.
  • Never exploit a discovered vulnerability beyond the minimum required to prove a proof-of-concept.

3. How to Submit a Vulnerability Report

Please send detailed findings to our engineering and security team:

In your report, please include:

  • Target URL and vulnerable component or parameter
  • Step-by-step reproduction steps or proof-of-concept script
  • Estimated severity and potential business impact
  • Proposed remediation advice (if applicable)

We aim to acknowledge reports within 3 business days and provide regular status updates during investigation and resolution.