Security

Responsible Disclosure

Wild Circle Dynamics LTD welcomes responsible security research and is committed to working with the security community to identify and resolve vulnerabilities in our website, applications, APIs and infrastructure. This policy explains how to report vulnerabilities to us, what you can expect in return, and the rules we ask researchers to follow. It is designed to comply with UK law, including the Computer Misuse Act 1990, the Data Protection Act 2018 and the UK GDPR.

1. Our commitment

We believe that responsible disclosure is essential to maintaining the security of our services and the data entrusted to us. We will not take legal action against anyone who reports security vulnerabilities to us in good faith and in accordance with this policy. We will treat all reports confidentially and work to resolve confirmed issues promptly.

2. Scope

This policy applies to the following systems and assets operated by Wild Circle Dynamics LTD:

  • our public website and associated domains;
  • our customer-facing SaaS platform and web application;
  • our public APIs and API documentation;
  • mobile-responsive versions of the above;
  • any other systems or services we explicitly include in scope.

If you are unsure whether a particular system or asset is in scope, please contact us before conducting any testing. We will do our best to confirm whether testing is authorised.

3. Out of scope

The following activities are not authorised and should not be attempted:

  • testing or attacking systems that are not owned or operated by Wild Circle Dynamics LTD;
  • denial of service (DoS) attacks, distributed denial of service (DDoS) attacks or resource exhaustion;
  • brute-forcing user accounts, credential stuffing or password spraying;
  • social engineering, phishing or pretexting targeting our staff, customers or users;
  • physical access attempts, tailgating or attacks on our premises;
  • spam, automated scraping or mass distribution of content unrelated to vulnerability research;
  • any activity that degrades the availability, integrity or confidentiality of user data;
  • exploiting vulnerabilities to access, modify, delete or exfiltrate data that does not belong to you;
  • installing malware, backdoors or persistent access mechanisms;
  • any testing that violates applicable law, including the Computer Misuse Act 1990.

4. Rules of engagement

To ensure responsible and lawful research, we ask that you:

  • make every effort to avoid harming users, data, systems or availability;
  • use only test accounts and non-production data wherever possible;
  • limit the scope and duration of your testing to what is necessary to confirm the vulnerability;
  • do not access, view, modify, delete or exfiltrate data belonging to others;
  • do not publicly disclose the vulnerability before we have had a reasonable opportunity to fix it;
  • provide us with sufficient detail to reproduce and understand the issue;
  • keep information about the vulnerability confidential until we authorise disclosure;
  • securely delete any data, files or credentials obtained during research after the issue is resolved;
  • do not request or accept payment in exchange for withholding disclosure.

5. How to report

Please send vulnerability reports toinfo@wildcircledynamicsltd.com with the subject line "Security Disclosure". Where possible, please encrypt sensitive information or use a secure communication channel.

A good report should include:

  • a clear description of the vulnerability and the system or URL affected;
  • the type of vulnerability (for example, XSS, SQL injection, broken access control, information disclosure);
  • step-by-step instructions to reproduce the issue;
  • the potential impact and who could be affected;
  • any proof-of-concept code, screenshots, videos or supporting evidence;
  • whether you have accessed, modified or retained any data;
  • your contact details and any publication or acknowledgement preferences;
  • whether you would like to be credited publicly or remain anonymous.

6. Safe harbour

If you comply with this policy and act in good faith, we consider your research to be authorised and we will not pursue legal action against you or report you to law enforcement for activities that would otherwise be prohibited by the Computer Misuse Act 1990 or related laws.

This safe harbour applies only to systems and activities that are within the scope of this policy. It does not apply to illegal activity, malicious acts, or testing of out-of-scope systems. We reserve the right to revoke safe harbour if you act in bad faith or breach the rules of engagement.

7. What you can expect from us

When we receive a report, we will aim to:

  • acknowledge receipt of your report within 5 business days;
  • assess the validity and severity of the reported issue;
  • assign a unique reference number for tracking purposes;
  • work to confirm, prioritise and remediate the vulnerability;
  • keep you informed of our progress, subject to confidentiality and legal constraints;
  • notify you when the issue has been resolved or mitigated;
  • credit you in any public disclosure or security advisory if you wish and if the issue warrants it.

8. Disclosure timeline

We aim to respond to reports promptly, but remediation timelines depend on the nature and severity of the issue. As a general guide:

  • Critical: initial response within 2 business days, remediation target 7 calendar days;
  • High: initial response within 3 business days, remediation target 14 calendar days;
  • Medium: initial response within 5 business days, remediation target 30 calendar days;
  • Low: initial response within 10 business days, remediation target 60 calendar days.

These timelines are targets and may be affected by complexity, dependencies, holidays or other factors. We will communicate with you if timelines change.

9. Coordinated disclosure

We request that researchers do not publicly disclose details of a vulnerability until we have had a reasonable time to fix it. We consider a reasonable time to be at least 90 calendar days from the date we acknowledge receipt of a complete report, unless otherwise agreed in writing.

If we have not resolved the issue within 90 days and have not provided a clear reason for the delay, you may disclose limited information in a responsible manner that minimises risk to users. We encourage coordinated disclosure where the report and our remediation are published together.

10. Recognition

We are grateful to the security community for helping us improve our security. With your permission, we may publicly acknowledge your contribution on a security acknowledgements page or in a security advisory. Recognition is provided at our discretion and is not guaranteed. We do not operate a formal bug bounty or paid vulnerability reward programme.

11. Handling of personal data

If your report includes personal data, we will handle it in accordance with our Privacy Policy and applicable data protection law. Please do not send us personal data of other individuals unless it is strictly necessary to demonstrate the vulnerability, and minimise the amount of data involved.

12. Interaction with law enforcement

If a reported vulnerability involves or may involve illegal activity, we may be required to report the matter to law enforcement or regulatory authorities. We will handle such matters in accordance with our legal obligations and will take into account the good-faith nature of responsible disclosure.

13. Changes to this policy

We may update this Responsible Disclosure Policy from time to time to reflect changes in our services, scope or legal requirements. The latest version will always be published on this page.

14. Contact

If you have any questions about this policy or wish to discuss a report before submitting it, please contact us:

Wild Circle Dynamics LTD
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Company number: 17371923
Email: info@wildcircledynamicsltd.com

Cookies

We use cookies to improve your experience and understand how our site is used. By continuing, you agree to our use of cookies. You can read more in our Cookie Policy.