Passbeam

Reporting a security issue

Last updated 7 September 2026.

If you have found a security problem in Passbeam, please tell us before telling anyone else.

Email support@passbeam.co.uk with Security at the start of the subject line. That address becomes a tracked ticket that a person reads — the same queue customers use, which is deliberate: a dedicated address nobody watches is worse than a shared one somebody does.

Please include, as far as you can:

  • what you did, in enough detail to repeat it
  • what happened, and what you expected instead
  • which hostname or endpoint, and roughly when
  • whether you were signed in, and to your own account or a test one

We will reply as soon as we can, and aim to do so within two working days. If a fix is needed, you will hear when it has shipped.

Please don’t, while you are looking

Passbeam authenticates devices onto other people’s networks, so some of the usual testing moves land on somebody who did not agree to them.

  • Don’t test against a customer’s tenant, network or equipment. Use your own account and your own hardware. Sign up if you need one.
  • Don’t attempt denial of service, including against the RADSec and RADIUS listeners. They are the part of this product whose failure stops people getting onto their own Wi-Fi.
  • Don’t access, keep or share data that is not yours. If a bug exposes somebody else’s data, stop, tell us what you saw and roughly how much, and delete it.
  • Don’t point automated scanners at the authentication listeners. They are on the public internet by necessity, and that traffic is indistinguishable from an attack.

What we will and will not do

Good-faith research, reported privately, is welcome. If you stay within the lines above we will not pursue you, and we will not ask your hosting provider or your employer to.

There is no bug bounty. Passbeam is run by one person and cannot honestly promise payment. We will credit you by name or handle if you would like, and say plainly what your report changed.

Scope

In scope: passbeam.co.uk and its subdomains, and the RADSec and RADIUS listeners Passbeam operates.

Out of scope, because they are not ours to authorise testing against: a customer’s Microsoft Entra tenant, a customer’s network equipment, and Microsoft’s own services. A report that Passbeam asks Microsoft for more permission than it needs is in scope and worth sending.