Security & Vulnerability Disclosure

Reporting a security vulnerability to Cscope

Cscope is committed to the security of our products and the safety of the people who use them. We welcome reports from security researchers, customers and members of the public who believe they have found a security vulnerability in one of our products or online services.

This page explains how to report a vulnerability to us safely, what you can expect from us in return, and the boundaries of our Coordinated Vulnerability Disclosure (CVD) programme. It is maintained as part of our obligations under the EU Cyber Resilience Act (Regulation (EU) 2024/2847) and follows the principles set out in ISO/IEC 29147 (Vulnerability Disclosure) and ISO/IEC 30111 (Vulnerability Handling).

Scope

This policy applies to security vulnerabilities affecting:

– Cscope products with digital elements, including our locators, transmitters, and any associated firmware, embedded software or companion applications.

– Cscope websites and web services, including `cscope.co.uk`, `cslocators.com`, and `cscopelocators.com`, together with any customer portals, APIs or connected online services we operate.

If you are unsure whether something falls within scope, please contact us using the details below before testing, we would rather hear from you than have you hold back a genuine concern.

Out of scope. The following are generally not eligible under this policy and should not be reported as product security vulnerabilities:

– Findings on third-party services, platforms or products we do not operate or manufacture.

– Reports produced solely by automated scanners without a demonstrable, exploitable impact.

– Volumetric or denial-of-service (DoS/DDoS) attacks, or any testing that degrades or disrupts our services.

– Social engineering, phishing, or physical attacks against Cscope staff, offices or infrastructure.

– Missing “best practice” hardening (e.g. absent security headers, SPF/DMARC configuration, TLS version preferences) with no demonstrable security impact.

Safe Harbour

Cscope will not pursue or support legal action against security researchers who, in good faith, discover and report a vulnerability in accordance with this policy.

Specifically, if you comply with this policy we will:

– Consider your research to be authorised under the UK Computer Misuse Act 1990 and any applicable equivalent legislation, and will not initiate or recommend legal action against you in connection with your report.

– Work with you to understand and resolve the issue quickly, and will not ask internet service providers or law enforcement to take action against you.

– Treat you as a good-faith contributor to the security of our products.

This safe harbour applies only where you:

– Act in good faith and avoid privacy violations, data destruction, service disruption, or degradation of the user experience.

– Only access, store or view the minimum data necessary to demonstrate a vulnerability, and do not access, modify or delete data belonging to others.

– Do not exploit a vulnerability beyond what is necessary to confirm its existence.

– Do not publicly disclose the vulnerability, or share it with any third party, before we have had a reasonable opportunity to resolve it and have agreed the timing of disclosure with you (see *Coordinated Disclosure* below).

– Comply with all applicable laws.

If legal action is initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorisation known.

If at any point you are uncertain whether a specific action is consistent with this policy, please pause and contact us first.

How to Report a Vulnerability

Please send your report to our dedicated security team:

Email: [email protected]

(alias monitored solely by the Cscope technical security team)

Where your report contains sensitive details, please encrypt it using our public PGP key (provided below) before sending.

What to include in your report

To help us triage and resolve the issue quickly, please include as much of the following as you can:

– The website or service affected (and version / firmware number where known).

– A clear description of the vulnerability and its potential impact.

– Step-by-step instructions to reproduce the issue, including any proof-of-concept code, scripts, screenshots or request/response captures.

– Any IP addresses, URLs or accounts used during your testing, and the approximate date and time of testing.

Reports may be submitted anonymously. However, providing contact details allows us to ask follow-up questions and keep you updated.

Please submit reports in English where possible.

What You Can Expect From Us

When you report a vulnerability in line with this policy, Cscope commits to the following:

Acknowledgement We will acknowledge receipt of your report within 2 business days (48 hours).

Triage & validation We will validate the report and confirm its scope and severity within 10 business days, and let you know our initial assessment.

Progress updates We will keep you informed of our progress at least every 14 days until the issue is resolved.

Resolution We aim to remediate confirmed vulnerabilities as quickly as is reasonably practicable, prioritised by severity, and will notify you when a fix or mitigation is in place.

Coordinated disclosure We will agree the timing of any public disclosure with you (see below).

Timelines refer to UK business days and may extend for complex issues, in which case we will keep you informed.

Where a vulnerability is actively exploited or constitutes a severe incident, Cscope may be legally required to notify the relevant national Computer Security Incident Response Team (CSIRT) and ENISA under the EU Cyber Resilience Act. Your report may form part of that assessment; we will handle your information confidentially throughout.

Coordinated Disclosure

We believe in coordinated, responsible disclosure that protects users while giving credit to researchers.

– We ask that you give us a reasonable period to remediate a vulnerability before disclosing it publicly. As a guideline, we work to a 90-day coordinated disclosure window from the date we acknowledge your report, extendable by mutual agreement where a fix is complex.

– We will work with you to agree a disclosure date and, where appropriate, to co-ordinate the publication of an advisory.

– Please do not disclose vulnerability details publicly, or to any third party, until we have confirmed the issue is resolved or the agreed disclosure date has been reached.

Recognition

Cscope does not currently operate a paid bug bounty programme. However, we are grateful to the researchers who help keep our products and customers secure. With your consent, we are happy to publicly acknowledge your contribution once an issue has been resolved.

security.txt

In line with [RFC 9116](https://www.rfc-editor.org/rfc/rfc9116), a machine-readable `security.txt` file is published at `/.well-known/security.txt` on each of our domains, pointing security researchers to this policy and our contact details.

*This policy may be updated from time to time. Please refer to this page for the current version.*

Last updated: 05/08/2026

How can we help you?

Talk to our experts on:

+44 (0)1233 629 181

-OR-

Submit an enquiry

How can we help you?