Muhammad Tahir Zaman Ltd (Company No. 16821325) prioritizes the privacy, confidentiality, and technical security of our clients and web visitors. This document details our baseline security controls and safe vulnerability reporting process.
1. Platform Security Measures
We maintain high standards of security across our web presence and client workflows:
- Transport Layer Security (HTTPS): All web traffic is encrypted in transit using industry-standard TLS protocols with HSTS preloading.
- Zero Financial Credential Storage: We never request, process, or store credit card numbers, online banking passwords, or account PINs on our website. All payout rails (Wise, PayPal, Tide) are configured directly by clients on official third-party portals.
- Form Abuse & Anti-Spam Protections: Our consultation forms incorporate multi-layered defences including Google reCAPTCHA v3 bot verification, honeypot traps, and client-side submission rate limiting to prevent denial-of-service and inbox flooding.
- Input Sanitization: All form inputs are strictly validated against restrictive length and regex patterns to mitigate cross-site scripting (XSS) and injection attacks.
- Third-Party Processor Vetting: Outbound lead delivery partners (FormSubmit.co, EmailJS) are vetted for compliance with UK and international data protection standards.
2. Vulnerability Disclosure Policy
We welcome contributions from cybersecurity professionals and ethical researchers. If you identify a security vulnerability within our web assets, we encourage you to report it to us responsibly.
Scope
The scope includes the web application hosted at muhammadtahirzamanltd.com and related public-facing subdomains.
Safe Harbor & Guidelines
We commit not to pursue legal action against researchers who adhere to the following principles:
- Act in good faith to avoid privacy violations, data destruction, and service interruption.
- Do not execute Denial of Service (DoS/DDoS) attacks or automated brute-force scanning that degrades website availability.
- Do not access, download, or alter client data or communications.
- Provide a reasonable timeframe (standard 90-day disclosure period) to allow our team to investigate and remediate findings before public release.
- Never exploit a discovered vulnerability beyond the minimum required to prove a proof-of-concept.
3. How to Submit a Vulnerability Report
Please send detailed findings to our engineering and security team:
Security Contact:
muhammadtahirzaman.ltd@gmail.com
Email Subject: [Security Vulnerability Report] <Brief Description>
In your report, please include:
- Target URL and vulnerable component or parameter
- Step-by-step reproduction steps or proof-of-concept script
- Estimated severity and potential business impact
- Proposed remediation advice (if applicable)
We aim to acknowledge reports within 3 business days and provide regular status updates during investigation and resolution.