Legal

Responsible Disclosure Policy

We would rather hear about a weakness from you than from an attacker. This policy explains how to report one, what we will do about it, and the protections you have when you report in good faith.

REPORT TO
support@cipherknights.com
ACKNOWLEDGEMENT
Within 2 working days
SAFE HARBOUR
Yes, for good-faith research
MACHINE-READABLE
/.well-known/security.txt
IN EFFECT FROM
9 September 2026
In short

How do I report a security vulnerability to Cipher Knights?

Email support@cipherknights.com with the affected URL or system, the steps to reproduce, and what an attacker could achieve. We acknowledge reports within two working days. Good-faith research under this policy is welcome and we will not pursue legal action over it. Please do not access other people data or disrupt the service.

Why this policy exists

We sell security. It would be inconsistent to ask our clients to run vulnerability assessments and then make it hard for anyone to tell us about a weakness in our own systems.

CIPHER KNIGHTS LTD is a small team, and we are realistic about that: we do not run a staffed 24/7 security operations centre, and this policy sets out timescales we can actually meet rather than ones that sound impressive. If you report something serious we will treat it seriously.

How to report

Email support@cipherknights.com. Put "Security" in the subject line so it is routed correctly. Our machine-readable contact details are published at /.well-known/security.txt in line with RFC 9116.

A report is much easier to act on when it includes the following. If you only have some of it, send what you have rather than nothing.

  • The URL, IP address or system affected
  • The type of issue, for example cross-site scripting or access control
  • Steps to reproduce it, or a short proof-of-concept
  • What an attacker could realistically achieve with it
  • Whether you have shared the finding with anyone else, and any timeline you intend to work to
  • How you would like to be credited, or that you would prefer to stay anonymous

What we will do

Timescales run from receipt, during UK business hours, Monday to Friday. A report sent late on a Friday will be picked up the following week.

  • Acknowledge your report within two working days
  • Give you an initial assessment of severity within ten working days
  • Keep you informed while we work on a fix, and tell you when it is deployed
  • Credit you publicly if you would like us to, once the issue is resolved
  • Tell you plainly if we decide not to act, and why

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will treat your activity as authorised, and we will not bring a civil claim against you or refer you to the police in connection with it. If a third party brings a claim against you over research that complied with this policy, we will confirm on request that your activity was authorised by us.

Two limits on that, so there is no misunderstanding. We may still have to make a report we are legally required to make - for example, notifying the Information Commissioner within 72 hours if a report shows that someone else personal data has been exposed. And if what actually happened was not good-faith research, this policy does not apply to it at all.

This authorisation extends only to systems that Cipher Knights owns and operates, and only to the extent that we are able to give it. It cannot authorise anything on infrastructure belonging to our hosting providers or other third parties, and it does not displace the Computer Misuse Act 1990 where you go beyond what is described here.

What is in scope

This policy covers systems that Cipher Knights owns and controls.

  • cipherknights.com and its subdomains
  • The client portal and document signing system
  • Email and DNS configuration for cipherknights.com

What is out of scope

Some of the items below are excluded because they would harm the service or other people; others because we cannot authorise testing that is not ours to authorise.

  • Client systems. Our clients systems are not ours to authorise testing on, so nothing in this policy authorises it and the safe harbour above does not extend to it. Finding a Cipher Knights logo on a client site does not change that. Testing without the system owner permission risks an offence under the Computer Misuse Act 1990. Contact that organisation directly.
  • Denial of service, load testing, or anything that degrades the service for other users
  • Social engineering, phishing, or any approach directed at our staff, our clients or our suppliers
  • Physical attacks against our premises or equipment
  • Third-party services we merely consume, such as our payment provider or scheduling tool. Report those to the vendor under their own policy.
  • Accessing, modifying or downloading data belonging to anyone else. Stop as soon as you have shown access is possible, and tell us.
  • Automated scanning that generates heavy traffic

Findings we generally will not act on

These are reported often and rarely represent real risk on a site like ours. We will still read your report, but a scanner output alone is unlikely to lead to a change. If you can show real impact, say so and we will look properly.

  • Missing security headers with no demonstrated exploit
  • Reports produced solely by an automated scanner, with no verification
  • Missing SPF, DKIM or DMARC records on domains that never send email
  • Software version disclosure without a working exploit
  • Self-XSS, or issues that require the victim to paste code into their own console
  • Clickjacking on pages with no state-changing action
  • Weaknesses that need a rooted device, a compromised network, or physical access

Coordinated disclosure

We ask that you give us a reasonable opportunity to fix an issue before making it public. Ninety days from your report is the norm, and we will usually be much faster than that. If a fix is going to take longer, we will tell you why and agree a revised date with you rather than let the deadline pass in silence.

If you believe an issue is being actively exploited, say so in your first email and we will prioritise it.

Rewards

We do not operate a paid bug bounty. We are a small company and we would rather say that plainly than advertise a programme we cannot fund consistently.

What we do offer is a genuine response from a person, public credit if you want it, and a written reference describing your finding if that would be useful to you professionally.

Who this policy is open to

Anyone may report a vulnerability to us, and we will act on a good report whoever it comes from. The safe harbour above is narrower, because there are people we are not free to extend it to.

  • It does not apply where a payment, credit or reference would breach UK sanctions, export controls or any other legal restriction that binds us
  • It does not apply to current or former Cipher Knights staff or contractors using knowledge or access obtained in that role, whose obligations are set by their contract instead
  • It does not apply where the activity was not good-faith research

Changes to this policy

We may update this policy. The version that applies to your research is the one published when you began it, so a later change cannot remove protection you already had. The date this version took effect is shown at the top of the page.

Your personal data

If you report a vulnerability we will hold your name and contact details for as long as needed to investigate, fix and follow up on the report, and to keep a record that the issue was handled. Our lawful basis is legitimate interests, namely keeping our systems secure.

You can report anonymously. We will not be able to credit you or come back with questions, but the report will still be acted on. Our privacy policy explains your rights and how to exercise them.

What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Frequently asked questions

Responsible Disclosure Policy — your questions answered

Do you pay for vulnerability reports?
No. We do not run a paid bug bounty and would rather say so than advertise a programme we cannot fund. We offer public credit, a real response from a person, and a written reference describing your finding if that is useful to you.
Can I test a client system that Cipher Knights built or manages?
No. This policy authorises testing of systems Cipher Knights owns and operates. A client system is not ours to authorise, and testing it without the system owner permission risks an offence under the Computer Misuse Act 1990. Contact that organisation directly.
How quickly will you respond?
We acknowledge reports within two working days and give an initial severity assessment within ten. Timescales run during UK business hours, Monday to Friday, so a report sent on a Friday evening is picked up the following week.
Will you take legal action against me?
Not for good-faith research that follows this policy. We will not report you to the police or bring a civil claim, and if a third party takes action over research that complied with this policy we will confirm that your activity was authorised.
Can I report anonymously?
Yes. We will not be able to credit you or ask follow-up questions, but the report will still be investigated and fixed.
Where are your machine-readable security contact details?
At https://cipherknights.com/.well-known/security.txt, published in the format set out in RFC 9116. It carries the reporting address, preferred language and an expiry date.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about responsible disclosure policy?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.