Legal hub

Security & Responsible Disclosure

Last updated September 13, 2026

This page describes our approach to security at a high level. We deliberately keep it general: it does not describe internal architecture, configuration or anything that would help someone attack the service.

1. How we protect information

  • Traffic between your browser and Own Ahead is encrypted in transit.
  • Passwords are handled by our authentication provider and stored only in hashed form; Own Ahead staff cannot read them.
  • Database access rules restrict private fields — such as exact street addresses, source references and representative contact details — so they are not readable by general marketplace traffic.
  • Private listing detail is released only after a server-side entitlement check for an eligible account.
  • Administrative access follows least privilege and is limited to the people who need it.
  • Card details are entered on our payment processor's hosted pages; Own Ahead does not receive or store full card numbers.
  • Our hosting and database providers operate managed backups and platform monitoring, and we review error and request logs for signs of abuse.

2. No system is completely secure

No product, provider or process can guarantee absolute security. We work to reduce risk and respond quickly, but we cannot promise that unauthorised access, loss or disclosure will never happen. Please use a strong, unique password and keep your account credentials private.

3. Responsible disclosure

If you believe you have found a vulnerability, we would like to hear from you. Please report it privately before disclosing it anywhere else, and give us reasonable time to investigate and fix it.

  • Include enough detail to reproduce the issue, and the date and time of your testing.
  • Do not access, modify, delete or retain data that is not your own, and stop as soon as you confirm the issue.
  • Do not run denial-of-service tests, spam, social engineering, physical intrusion or automated scanning that degrades the service.
  • Do not exploit an issue beyond what is needed to demonstrate it, and do not publish user data.

We do not currently operate a paid bug-bounty programme. We will acknowledge good faith reports and will not pursue action against researchers who follow this guidance.

Own Ahead does not yet publish a dedicated legal or privacy mailbox. Until one is in place, send any legal, privacy, accessibility, copyright or security message through the privacy and requests centre. Requests submitted there are logged for review, and you do not need an account to use it.

4. If something happens

If we become aware of an incident affecting personal information, we will investigate, take steps to contain it, and notify affected users and regulators where the law requires it. A documented incident-response process is being finalised as part of our launch preparation.