Security & Responsible Disclosure
Last updated: 25 August 2026
1. Security at ClinCore
Security and the responsible handling of information are important considerations in how ClinCore Systems Ltd (“ClinCore”, “we”, “us” or “our”) designs and operates its technology.
This page provides a high-level overview of our current approach to website and information security and explains how to report a potential security issue responsibly.
It is intentionally not a technical architecture document.
2. Our security principles
Our current approach is guided by the following principles:
Information should only be accessible to people and systems that have a legitimate need to access it.
Information and systems should be protected against unauthorised or inappropriate alteration.
Technology should be designed and operated with appropriate consideration for reliability, recovery and continuity.
Access should be limited to what is reasonably needed for the relevant role or function.
We aim to avoid collecting or retaining personal information that is not needed for the relevant purpose.
Security and privacy considerations should be incorporated into changes, new features and data-processing activities rather than added only afterwards.
3. Website and information security
For the public website, ClinCore uses proportionate technical and organisational controls including encrypted connections, access controls, secure configuration, validation and appropriate security review.
We do not publish detailed internal security architecture or configuration information.
4. Sensitive information and public website forms
Our public website forms are not intended to receive patient-identifiable information, sensitive clinical information, passwords or authentication credentials.
Please do not include that information in a contact, demo or support request.
Where customer organisations use ClinCore software under a formal agreement, relevant information-security, data-processing and technical requirements may be addressed separately through the applicable contractual and technical documentation.
5. Third-party service providers
ClinCore uses selected third-party technology and service providers to operate parts of its website and business.
We consider appropriate privacy and security requirements when selecting and using suppliers that process information on our behalf.
Our Privacy Notice provides more information about relevant service providers and international data processing.
A provider's certification or assurance status must not be presented as a ClinCore certification unless ClinCore itself has independently achieved that status.
6. Certifications and assurance
Any certifications, accreditations or independent assurance held by ClinCore will only be stated publicly where they have been formally achieved and can be verified. Certifications or assurance held by our technology providers should not be interpreted as certifications held by ClinCore itself.
7. Responsible security disclosure
We welcome good-faith reports of potential security issues affecting the ClinCore public website.
To report a potential vulnerability, email: hello@clincoresystems.co.uk
Suggested email subject: Security disclosure
Where possible, please include:
- a clear description of the issue;
- the affected page or function;
- steps to reproduce the issue, where appropriate;
- the potential impact; and
- contact details if you would like a response.
Please do not:
- access, alter, copy or delete data that does not belong to you;
- attempt to obtain patient-identifiable or sensitive clinical information;
- disrupt or degrade our services;
- perform denial-of-service testing;
- use social engineering against ClinCore personnel or suppliers;
- exploit a vulnerability beyond what is reasonably necessary to demonstrate it;
- publicly disclose a suspected vulnerability before ClinCore has had a reasonable opportunity to investigate it; or
- include patient-identifiable information, sensitive clinical information, passwords or authentication credentials in your report.
We do not currently operate a public bug-bounty programme and we do not promise a financial reward for vulnerability reports.
Nothing on this page creates a contractual safe-harbour commitment beyond rights and protections already provided by applicable law.
8. Privacy
For information about how ClinCore handles personal information, see our Privacy Notice.
9. Contact
Company No. 17342096
88 Moorfield Avenue
Blackburn
BB1 9BU
United Kingdom
Email: hello@clincoresystems.co.uk