Skip to main content

Defenders of Access to Justice

Our public thanks to the security researchers who have helped protect the people who use BundleCreator — litigants in person, domestic abuse survivors, SEND families, housing disrepair claimants and others who depend on the justice system but often cannot afford legal representation.

BundleCreator is a small, bootstrapped UK team. We do not pay financial rewards for security research. What we offer is our thanks, public recognition here, a signed certificate of contribution, and the knowledge that your work has real and direct impact on vulnerable users of the justice system.

You have our gratitude — and that of the people we serve.

Found an issue?

Read our disclosure policy, then email your report.

2026

  • Karan RathodMedium

    Raised the account password strength bar across the platform, protecting every user's bundle data from credential-guessing attacks — including domestic abuse survivors, SEND families and litigants in person.

    April 2026
  • Identified a parallel-request race condition in the bundle-sharing flow, closing a class of concurrency vulnerability and prompting a platform-wide audit of limit checks — hardening the service that supports litigants in person, domestic abuse survivors and SEND families.

    April 2026

Defender of the Year

Each year we recognise one researcher whose work has had the greatest impact on our users' safety. The Defender of the Year receives a dedicated write-up on our blog, a framed letter of thanks from the founder, and the standing thanks of everyone at BundleCreator.

No award has yet been made. We look forward to recognising our first Defender of the Year.