AboutPlatformModulesSolutionsFAQUpdates
Sign inBook a demo
Policies
Privacy PolicyPatient PrivacyYour Data RightsData ComplaintsAppropriate Policy DocCookiesWebsite TermsPlatform TermsAcceptable UseAccessibilityResponsible Disclosure
Cannexis Biopharma
ClinicalFlow Platform

Responsible Disclosure Policy

Applies to: cannexis.org & the ClinicalFlow platform  |  Effective: 29 June 2026  |  FINAL v1.0 — approved for publication

Website & platform — security

1. Our commitment to security

Cannexis Biopharma Ltd operates a platform that handles sensitive health data, and we take security seriously. We welcome reports from security researchers and users who find potential vulnerabilities, and we will work with you to verify and fix them.

2. Scope

This policy covers cannexis.org, the ClinicalFlow platform at app.cannexis.org, and its API at app.cannexis.org/api. Our underlying cloud infrastructure (Amazon Web Services, eu-west-2) and other third-party services we use are covered by their own vulnerability-disclosure programmes and are out of scope here.

3. How to report

Email security@cannexis.org with: a clear description of the issue, the steps to reproduce it, the systems affected, and any supporting evidence. Please report promptly and give us reasonable time to respond before any public disclosure.

4. Safe harbour

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your report as authorised access for the purpose of the Computer Misuse Act 1990.

5. What we ask of you

  • Do not access, modify, delete or download more data than is necessary to demonstrate the issue — and never access another person's personal or health data;
  • Do not disrupt our services (no denial-of-service, spam or social-engineering of staff or patients);
  • Keep the details confidential until we confirm the issue is resolved;
  • Act lawfully throughout.

6. Out of scope

The following are generally not in scope: denial-of-service (volumetric or resource-exhaustion) attacks; social engineering or phishing of our staff, patients or tenants; physical attacks against offices or staff; issues in third-party services (e.g. our cloud provider); spam, rate-limiting or email-deliverability findings (SPF/DKIM/DMARC) without a demonstrated exploit; missing security headers or best-practice suggestions with no realistic exploit; reports generated solely by automated scanners without a working proof of concept; and self-XSS or issues requiring a fully compromised device.

7. What you can expect from us

  • Acknowledgement of your report within 3 working days;
  • An assessment and, where valid, a remediation plan, with updates on progress;
  • Recognition for your help if you wish. We do not currently operate a paid bug-bounty programme, but we are grateful for responsible disclosure and will credit you (with your permission).

8. Contact

security@cannexis.org. Data-protection concerns can also go to our DPO (below).

Cannexis Biopharma Ltd · Company no. 16387680 · Registered office: 142-143 Parrock Street, Gravesend, Kent, DA12 1EY · ICO registration: ZC164947
Data Protection Officer: LHI Consulting — info@lhiconsult.com · c/o Cannexis Biopharma Ltd, 142-143 Parrock Street, Gravesend, Kent, DA12 1EY
Cannexis
ClinicalFlow Platform

Cannexis is the multi-tenant telemedicine and shared-care platform purpose-built for UK medical cannabis. We are a technology layer for CQC-registered clinics, specialist prescribers, pharmacist IPs, dispensing pharmacies and their patients — not a clinic.

UK GDPRDSPT-alignedCQC-readyUK-hosted

Platform

  • Modules
  • For clinics
  • For clinicians
  • For pharmacies
  • For patients

Company

  • About
  • Updates
  • Book a demo
  • hello@cannexis.org
  • Gravesend, Kent, United Kingdom
© 2026 Cannexis Biopharma Ltd · Company no. 16387680 · UK data residency
AboutFAQContactPoliciesPrivacyCookiesTermsAccessibility