CyConex
Agentic Assurance Safe AI & data protection Features
NCSC CAF GovAssure Cyber Essentials NIST 800-53 NIST CSF 2.0 Custom frameworks
Continuous assurance Auditors & assessors Organisations being assessed Supply chain assurance For boards & SROs
Dashboards & heatmaps Report builder Board reporting
Articles Videos Trust centre Vulnerability disclosure Privacy Policy
Sign in
  1. Home/
  2. Vulnerability Disclosure Policy
← Back to home
Security

Vulnerability Disclosure Policy

We welcome responsible reports of security vulnerabilities affecting CyConex and related Clockwork Robot Ltd systems. This policy explains how to contact us, what is in scope, and how we handle disclosure.

Last updated: 16 September 2026

Privacy Policy Terms of Service Cookie notice Data Processing Agreement Vulnerability disclosure

1. Purpose

Clockwork Robot Ltd (trading as CyConex; UK Company Registration Number 17326205) is committed to the security of our products, websites, and customer environments. We encourage security researchers and customers to report potential vulnerabilities so we can investigate and remediate them promptly.

This Vulnerability Disclosure Policy describes the preferred way to report issues, the scope of systems covered, and what you can expect from us. It is intended to support coordinated, good-faith disclosure — not to authorise testing beyond the limits set out below.

2. Security contact

Please send vulnerability reports to website@clockwork-robot.co.uk.

Use a clear subject line such as "Vulnerability report: [product or URL]" so the message can be triaged quickly. Include enough detail for us to reproduce the issue.

If your report contains sensitive technical detail, you may encrypt the message where practical and note the encryption method in your email. We will acknowledge receipt and follow up from the same address.

3. Scope

In-scope systems and assets include:

  • The CyConex product and related application services operated by Clockwork Robot Ltd.
  • Public websites we operate, including www.cyconex.com and www.clockwork-robot.co.uk.
  • APIs, authentication flows, and supporting infrastructure we control that are used to deliver those services.

Out of scope: third-party services we do not operate (for example customer Microsoft 365 tenants, social networks, or supplier platforms); physical security of offices; social engineering of staff or customers; denial-of-service or volumetric attacks; and spam or phishing campaigns.

If you are unsure whether something is in scope, email the security contact before testing further.

4. How to report

Helpful reports usually include:

  • A clear description of the vulnerability and its potential impact.
  • The affected URL, host, product area, or API endpoint.
  • Step-by-step reproduction instructions, including any required account role or configuration.
  • Proof of concept (screenshots, request/response samples, or a short video) where safe to provide.
  • Suggested remediation if you have one (optional).
  • Your preferred contact details and whether you wish to be credited if we publish an advisory.

Please report one issue per message where practical, and avoid including personal data belonging to third parties unless it is essential to demonstrate the vulnerability.

5. Rules of engagement

We ask that you act in good faith and avoid harm to our customers, staff, or services while investigating.

  • Do not access, modify, or delete data that is not your own.
  • Do not use vulnerabilities to pivot into other systems or customer environments.
  • Do not perform denial-of-service, resource exhaustion, or spam testing.
  • Do not attempt social engineering, phishing, or physical intrusion.
  • Do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate, unless we agree otherwise in writing.
  • Stop testing and notify us immediately if you encounter personal data, credentials, or other sensitive material beyond what is needed to demonstrate the issue.

This policy does not grant permission to break the law. Activities that go beyond good-faith research into systems we operate may be reported to law enforcement. Where you follow this policy in good faith, we will not pursue civil legal action relating to that research.

6. What we will do

When we receive a valid report, we aim to:

  • Acknowledge receipt within five business days.
  • Assess severity, impact, and affected systems.
  • Keep you informed of material progress where you have provided a contact address.
  • Remediate confirmed issues according to risk and operational constraints.
  • Notify you when a fix is available or when we have closed the report with our conclusion.

Target timelines may vary with complexity, dependency on third parties, and the need to coordinate customer communication. Critical issues will be prioritised.

We do not currently operate a paid bug bounty programme. We may offer public thanks or credit with your consent when we publish security information.

7. Coordinated disclosure

We prefer coordinated disclosure. Please allow us a reasonable period to investigate and remediate before any public discussion of technical details that could enable exploitation.

As a guide, we ask for at least 90 days from our acknowledgement for non-critical issues, unless we agree a different timeline. For critical issues we may ask for more or less time depending on remediation progress and customer impact.

If an issue is already being actively exploited, or if regulatory or customer notification obligations require earlier communication, we may disclose or notify independently of any researcher publication plans.

8. Safe harbour for good-faith research

If you comply with this policy, avoid privacy harm, and act without malicious intent, we consider your research authorised for the purposes of our systems and will not bring a claim against you for that research under civil law relating to computer misuse of those systems.

This safe harbour does not apply if you exploit a vulnerability beyond what is reasonably necessary to demonstrate it, demand payment as a condition of disclosure, or violate applicable criminal law.

9. Relationship to other policies

This policy covers security vulnerability reporting. Privacy questions and data subject requests are handled under our Privacy Policy. Product trust, hosting, and AI safety information is published on our Trust centre. Data processing terms for customers are summarised in our Data Processing Agreement.

All contact, including vulnerability reports and general enquiries, should be sent to website@clockwork-robot.co.uk. Use a clear subject line so messages can be triaged appropriately.

10. Updates

We may update this policy from time to time. The version published at this URL is the current policy. Material changes will be reflected in the "Last updated" date above.

Machine-readable contact details are also published at https://www.cyconex.com/.well-known/security.txt in accordance with RFC 9116.

CyConex

CyConex is an AI-assisted cyber assurance platform built for UK NCSC CAF assessments. Ingest evidence, assess contributing outcomes and IGPs, and export CAF heatmaps and audit-ready reports.

website@clockwork-robot.co.uk CyConex is owned by Clockwork Robot LtdCompany no. 17326205128 City Road, London EC1V 2NX CyConex on LinkedIn

Still under development · Contact us to keep in touch

Agentic AssuranceSafe AI & data protectionContinuous assuranceCyber EssentialsDashboards & heatmapsReport builderFor teamsFeaturesArticlesTrust centre

Topics

NCSC CAF assessment softwareGovAssure assessment softwareAI-assisted evidence reviewSharePoint evidence ingestionNIST 800-53 assessment softwareNIST CSF 2.0 assessment software

© 2026 Clockwork Robot Ltd. All rights reserved.

Privacy PolicyTerms of ServiceCookie noticeData Processing AgreementVulnerability disclosure

CyConex is still under development. Features described on this website may change. Contact us to keep in touch.