Vulnerability Disclosure Policy
We welcome responsible reports of security vulnerabilities affecting CyConex and related Clockwork Robot Ltd systems. This policy explains how to contact us, what is in scope, and how we handle disclosure.
Last updated: 16 September 2026
1. Purpose
Clockwork Robot Ltd (trading as CyConex; UK Company Registration Number 17326205) is committed to the security of our products, websites, and customer environments. We encourage security researchers and customers to report potential vulnerabilities so we can investigate and remediate them promptly.
This Vulnerability Disclosure Policy describes the preferred way to report issues, the scope of systems covered, and what you can expect from us. It is intended to support coordinated, good-faith disclosure — not to authorise testing beyond the limits set out below.
2. Security contact
Please send vulnerability reports to website@clockwork-robot.co.uk.
Use a clear subject line such as "Vulnerability report: [product or URL]" so the message can be triaged quickly. Include enough detail for us to reproduce the issue.
If your report contains sensitive technical detail, you may encrypt the message where practical and note the encryption method in your email. We will acknowledge receipt and follow up from the same address.
3. Scope
In-scope systems and assets include:
- The CyConex product and related application services operated by Clockwork Robot Ltd.
- Public websites we operate, including www.cyconex.com and www.clockwork-robot.co.uk.
- APIs, authentication flows, and supporting infrastructure we control that are used to deliver those services.
Out of scope: third-party services we do not operate (for example customer Microsoft 365 tenants, social networks, or supplier platforms); physical security of offices; social engineering of staff or customers; denial-of-service or volumetric attacks; and spam or phishing campaigns.
If you are unsure whether something is in scope, email the security contact before testing further.
4. How to report
Helpful reports usually include:
- A clear description of the vulnerability and its potential impact.
- The affected URL, host, product area, or API endpoint.
- Step-by-step reproduction instructions, including any required account role or configuration.
- Proof of concept (screenshots, request/response samples, or a short video) where safe to provide.
- Suggested remediation if you have one (optional).
- Your preferred contact details and whether you wish to be credited if we publish an advisory.
Please report one issue per message where practical, and avoid including personal data belonging to third parties unless it is essential to demonstrate the vulnerability.
5. Rules of engagement
We ask that you act in good faith and avoid harm to our customers, staff, or services while investigating.
- Do not access, modify, or delete data that is not your own.
- Do not use vulnerabilities to pivot into other systems or customer environments.
- Do not perform denial-of-service, resource exhaustion, or spam testing.
- Do not attempt social engineering, phishing, or physical intrusion.
- Do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate, unless we agree otherwise in writing.
- Stop testing and notify us immediately if you encounter personal data, credentials, or other sensitive material beyond what is needed to demonstrate the issue.
This policy does not grant permission to break the law. Activities that go beyond good-faith research into systems we operate may be reported to law enforcement. Where you follow this policy in good faith, we will not pursue civil legal action relating to that research.
6. What we will do
When we receive a valid report, we aim to:
- Acknowledge receipt within five business days.
- Assess severity, impact, and affected systems.
- Keep you informed of material progress where you have provided a contact address.
- Remediate confirmed issues according to risk and operational constraints.
- Notify you when a fix is available or when we have closed the report with our conclusion.
Target timelines may vary with complexity, dependency on third parties, and the need to coordinate customer communication. Critical issues will be prioritised.
We do not currently operate a paid bug bounty programme. We may offer public thanks or credit with your consent when we publish security information.
7. Coordinated disclosure
We prefer coordinated disclosure. Please allow us a reasonable period to investigate and remediate before any public discussion of technical details that could enable exploitation.
As a guide, we ask for at least 90 days from our acknowledgement for non-critical issues, unless we agree a different timeline. For critical issues we may ask for more or less time depending on remediation progress and customer impact.
If an issue is already being actively exploited, or if regulatory or customer notification obligations require earlier communication, we may disclose or notify independently of any researcher publication plans.
8. Safe harbour for good-faith research
If you comply with this policy, avoid privacy harm, and act without malicious intent, we consider your research authorised for the purposes of our systems and will not bring a claim against you for that research under civil law relating to computer misuse of those systems.
This safe harbour does not apply if you exploit a vulnerability beyond what is reasonably necessary to demonstrate it, demand payment as a condition of disclosure, or violate applicable criminal law.
9. Relationship to other policies
This policy covers security vulnerability reporting. Privacy questions and data subject requests are handled under our Privacy Policy. Product trust, hosting, and AI safety information is published on our Trust centre. Data processing terms for customers are summarised in our Data Processing Agreement.
All contact, including vulnerability reports and general enquiries, should be sent to website@clockwork-robot.co.uk. Use a clear subject line so messages can be triaged appropriately.
10. Updates
We may update this policy from time to time. The version published at this URL is the current policy. Material changes will be reflected in the "Last updated" date above.
Machine-readable contact details are also published at https://www.cyconex.com/.well-known/security.txt in accordance with RFC 9116.