Responsible Disclosure Policy
Website & platform — security
1. Our commitment to security
Cannexis Biopharma Ltd operates a platform that handles sensitive health data, and we take security seriously. We welcome reports from security researchers and users who find potential vulnerabilities, and we will work with you to verify and fix them.
2. Scope
This policy covers cannexis.org, the ClinicalFlow platform at app.cannexis.org, and its API at app.cannexis.org/api. Our underlying cloud infrastructure (Amazon Web Services, eu-west-2) and other third-party services we use are covered by their own vulnerability-disclosure programmes and are out of scope here.
3. How to report
Email security@cannexis.org with: a clear description of the issue, the steps to reproduce it, the systems affected, and any supporting evidence. Please report promptly and give us reasonable time to respond before any public disclosure.
4. Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your report as authorised access for the purpose of the Computer Misuse Act 1990.
5. What we ask of you
- Do not access, modify, delete or download more data than is necessary to demonstrate the issue — and never access another person's personal or health data;
- Do not disrupt our services (no denial-of-service, spam or social-engineering of staff or patients);
- Keep the details confidential until we confirm the issue is resolved;
- Act lawfully throughout.
6. Out of scope
The following are generally not in scope: denial-of-service (volumetric or resource-exhaustion) attacks; social engineering or phishing of our staff, patients or tenants; physical attacks against offices or staff; issues in third-party services (e.g. our cloud provider); spam, rate-limiting or email-deliverability findings (SPF/DKIM/DMARC) without a demonstrated exploit; missing security headers or best-practice suggestions with no realistic exploit; reports generated solely by automated scanners without a working proof of concept; and self-XSS or issues requiring a fully compromised device.
7. What you can expect from us
- Acknowledgement of your report within 3 working days;
- An assessment and, where valid, a remediation plan, with updates on progress;
- Recognition for your help if you wish. We do not currently operate a paid bug-bounty programme, but we are grateful for responsible disclosure and will credit you (with your permission).
8. Contact
security@cannexis.org. Data-protection concerns can also go to our DPO (below).
Data Protection Officer: LHI Consulting — info@lhiconsult.com · c/o Cannexis Biopharma Ltd, 142-143 Parrock Street, Gravesend, Kent, DA12 1EY
