Version 1.0 · effective 26 August 2026
Who you are dealing with
Plate Software is supplied by Paramount Plates Ltd, a company registered in England and Wales under company number 16366988, whose registered office is at 42 Moorside, Spennymoor, DL16 7EA, United Kingdom.
In this document, “we”, “us” and “our” mean Paramount Plates Ltd, and “you” means the business named at checkout.
You can reach us at hello@platesoftware.co.uk or on 0191 367 3451, Monday to Saturday, 8:00am to 4:30pm.
Reporting a security problem
Email hello@platesoftware.co.uk with “security” in the subject. Tell us what you found, how to reproduce it, and what you think the impact is.
We will acknowledge within two working days, tell you what we think within ten, and tell you when it is fixed.
What we promise you
If you follow this page, we will not take legal action against you and we will not treat your research as a breach of the licence agreement — including the restriction on reverse engineering, which we waive for this purpose.
That waiver is specific and it is genuine: you cannot find a fault in a desktop application without taking it apart, and it would be dishonest to invite reports while forbidding the only way to produce one.
We also give you a licence to install, run and examine Plate Software to look for faults in it, whether or not you are a customer. That licence makes you a lawful user, which is what the Copyright, Designs and Patents Act 1988 requires before its decompilation and study rights apply to you.
We will credit you when we publish the fix, unless you would rather we did not.
What we cannot promise
We can only give permission over things that are ours.
This website is served through Cloudflare, payments run through Stripe, our email goes through Resend, and our own mailbox is Google Workspace. Those systems belong to those companies, not to us. We cannot authorise you to test them and this page does not try to. If what you want to try would land on one of them, ask them rather than us.
We also cannot give you permission to touch another customer's computer, their installation or their files. Those are theirs to give.
What we ask of you
Test only against your own installation and your own data.
Do not access, modify or delete anyone else's data, and do not degrade the service for anyone else.
Give us a reasonable chance to fix it before telling anyone else — 90 days is the usual expectation, and less if it is being actively exploited.
Do not demand payment in exchange for withholding a report. The bug reporting scheme is separate, voluntary, and described on the support pages.
What is out of scope
Reports produced entirely by an automated scanner with no demonstrated impact. Missing headers or configuration findings with no exploit path. Social engineering of us or our customers. Physical attacks. Denial of service.
The application is currently distributed as an unsigned executable. We know, we are fixing it, and it does not need reporting.
Questions about any of this? Email hello@platesoftware.co.uk.