Complete Licensing is committed to protecting our customers, partners, staff and other internet users. We welcome responsible reports from security researchers and members of the public who believe they have identified a security vulnerability affecting our systems or services.

This policy establishes a coordinated and constructive process for reporting, investigating and resolving security vulnerabilities.

A security vulnerability is a weakness in a system or service that could compromise its confidentiality, integrity or availability.

Responsibility for this policy rests with the senior management team of Complete Licensing. The policy will be reviewed at least annually, and relevant staff will receive appropriate training.

Scope

This policy applies to websites, applications, systems and online services owned or controlled by Complete Licensing.

Third-party systems, services, platforms and infrastructure are not included merely because they are linked to, integrated with or used by Complete Licensing. If you believe a vulnerability in a third-party service affects Complete Licensing, please report it to us without conducting further testing of the third-party service.

If you are unsure whether a system is within scope, contact us before testing it.

Reporting Vulnerabilities

If you believe you have discovered a vulnerability in one of our services, or have a security incident to report, please email:

[email protected]

Please do not include passwords, payment details, unnecessary personal data or other sensitive information in your initial report. If sensitive material is essential, let us know and we will agree an appropriate secure method for providing it.

What to include

To help us assess and resolve the issue efficiently, please include:

  • The website, application, IP address or page where the vulnerability can be observed.

  • A brief description of the vulnerability and its potential impact.

  • Benign and non-destructive steps that allow us to reproduce the issue.

  • Any relevant screenshots, logs or proof-of-concept material.

  • The date and time the vulnerability was identified.

  • Your preferred contact details.

  • Whether you wish to be publicly acknowledged or remain anonymous.

Please provide only the information reasonably necessary to demonstrate the vulnerability.

What to Expect After Reporting

After receiving a vulnerability report, Complete Licensing will:

  • Acknowledge receipt as promptly as reasonably possible.

  • Review and triage the report.

  • Work with you to understand and investigate the vulnerability.

  • Tell you whether the vulnerability has been accepted and, where possible, provide an expected remediation timeframe.

  • Provide reasonable progress updates while the issue is being investigated.

  • Notify you when the vulnerability has been resolved.

  • Allow reasonable retesting, where appropriate, to confirm that the issue has been addressed.

  • Publicly acknowledge the reporter, where appropriate, unless the reporter wishes to remain anonymous.

Where appropriate, resolved vulnerabilities may be announced in release notes, security notices, blog posts or other public communications.

Complete Licensing will endeavour to keep the reporter informed throughout this process. However, operational, legal or security considerations may limit the information we can provide.

Rules of Engagement

To qualify for the Safe Harbor described below, you must act in good faith and follow these Rules of Engagement.

You must:

  • Make a genuine effort to avoid harming Complete Licensing, our customers, staff, suppliers and other users.

  • Test only systems and services owned or controlled by Complete Licensing.

  • Use only accounts that you own or have express permission to use.

  • Use benign, proportionate and non-destructive testing methods.

  • Access only the minimum amount of information reasonably necessary to demonstrate the vulnerability.

  • Stop testing and report the issue immediately if you encounter personal data, payment information, confidential business information, credentials or other sensitive information.

  • Protect any information obtained from unauthorised access, use, alteration, loss or disclosure.

  • Comply with applicable data protection requirements.

  • Report the vulnerability promptly through our official reporting channel.

  • Cooperate reasonably with our investigation and remediation process.

  • Securely delete information obtained during your research as soon as it is no longer needed, or within one month of the vulnerability being resolved, whichever occurs first, unless otherwise agreed or required by law.

You must not:

  • Break any applicable law or regulation.

  • Test systems or services belonging to a third party without that party’s permission.

  • Access, download, copy, alter or retain more data than is reasonably necessary to demonstrate the vulnerability.

  • Access another person’s account or data, except to the minimum extent accidentally encountered while identifying a vulnerability.

  • Modify or delete data belonging to Complete Licensing or another person.

  • Establish persistence, install malware, create backdoors or attempt to maintain access to a system.

  • Use high-intensity, invasive or destructive security-scanning tools that could affect the availability or quality of our services.

  • Conduct or attempt denial-of-service testing, including overwhelming a service with high-volume requests.

  • Perform social engineering, phishing or impersonation involving Complete Licensing staff, contractors, customers or suppliers.

  • Conduct physical security testing of our offices, facilities, staff or equipment.

  • Exploit a vulnerability beyond what is reasonably necessary to demonstrate that it exists.

  • Use a vulnerability or information obtained through research for personal, financial or commercial advantage.

  • Share, sell or transfer vulnerability information or information obtained from our systems.

  • Make threats, engage in extortion or make disclosure of the vulnerability conditional on receiving payment or another benefit.

  • Submit automated or low-value reports concerning TLS configuration, including reports limited to weak cipher-suite support or TLS 1.0 support.

  • Publicly disclose a vulnerability contrary to the coordinated disclosure requirements below.

This policy does not create an entitlement to a financial reward. Complete Licensing does not currently operate a public bug-bounty programme.

Coordinated Disclosure and Confidentiality

Please keep the vulnerability and our communications confidential while we investigate and remediate the issue.

You must not disclose the vulnerability to the public or to an unrelated third party until:

  • Complete Licensing confirms that the vulnerability has been mitigated or remediated; or

  • A disclosure date has been agreed with Complete Licensing in writing.

Complete Licensing will not unreasonably withhold or delay agreement concerning responsible public disclosure.

This restriction does not prevent you from notifying a third party where the vulnerability directly affects that third party. Where possible, please coordinate that notification with us so the vulnerability can be managed safely.

Legalities

This policy provides limited authorisation from Complete Licensing for good-faith security research conducted within its scope and in accordance with its Rules of Engagement.

It does not authorise conduct outside this policy, unlawful conduct, or conduct that could cause Complete Licensing to breach its legal obligations, including those arising under:

  • The Computer Misuse Act 1990.

  • The UK General Data Protection Regulation and the Data Protection Act 2018, as amended.

  • The Copyright, Designs and Patents Act 1988.

  • The Official Secrets Act 1989.

Researchers remain responsible for complying with all laws and regulations applicable to them.

Safe Harbor

Complete Licensing welcomes responsible security research that helps us protect our customers, partners, staff and services.

Where you conduct security research in good faith, on systems, websites or applications owned or controlled by Complete Licensing, and in accordance with this policy, we consider that research to be authorised by Complete Licensing.

For research covered by this Safe Harbor, Complete Licensing will:

  • Not initiate or support civil legal proceedings against you solely because of that research.

  • Not refer your activity to law enforcement or support criminal proceedings against you solely because of that research, unless we are required to do so by law.

  • Not bring or support a claim under applicable anti-circumvention or copyright laws where any circumvention was reasonably necessary and proportionate for research permitted by this policy.

  • Waive, on a limited basis, any restrictions in our Terms of Service, Acceptable Usage Policy or similar contractual terms that would otherwise prevent research permitted by this policy.

  • Treat your research and report as a good-faith contribution to the security of our services.

  • Work constructively with you to understand and resolve the reported vulnerability.

Meaning of good faith

Good faith means:

  • Acting with an honest intention to identify and help resolve a security vulnerability.

  • Taking reasonable precautions to prevent harm.

  • Using proportionate and non-destructive methods.

  • Accessing only the minimum information necessary to demonstrate the vulnerability.

  • Not misusing any information or access obtained.

  • Reporting the vulnerability promptly.

  • Following this policy as closely as reasonably possible.

A report made in good faith will not lose Safe Harbor protection merely because the reported issue is ultimately found not to be a vulnerability.

Accidental breaches of this policy

If you unintentionally go beyond the scope of this policy, you must:

  • Stop testing immediately.

  • Avoid accessing or using any additional information.

  • Protect any information already obtained.

  • Take reasonable steps to prevent or minimise harm.

  • Report what happened to us as soon as reasonably possible.

Where a breach was accidental and in good faith, and you act promptly to minimise harm and report the circumstances to us, Complete Licensing will extend this Safe Harbor to that accidental breach.

Exclusions from Safe Harbor

Safe Harbor does not apply to:

  • Deliberate, reckless or repeated breaches of this policy.

  • Malicious activity or activity intended to cause harm.

  • Extortion, threats or demands for payment.

  • Denial-of-service activity.

  • Social engineering, phishing or physical intrusion.

  • Intentional access to unnecessary personal, financial or confidential information.

  • Misuse, sale or public disclosure of information obtained during research.

  • Installing malware, establishing persistence or maintaining unauthorised access.

  • Testing third-party systems without permission.

  • Conduct that continues after we have asked you to stop for a legitimate security, legal or operational reason.

Third Parties and Limitations

This Safe Harbor applies only to rights and legal claims controlled by Complete Licensing.

Complete Licensing cannot bind third parties, service providers, law-enforcement bodies, prosecutors, regulators or courts. This policy does not provide an indemnity against action taken by an independent third party.

If a third party initiates legal action against you arising solely from research that complied with this policy, Complete Licensing will, where legally permitted, take reasonable steps to confirm that your activity was conducted in accordance with this policy.

Questions and Feedback

If you have concerns or are uncertain whether proposed research is consistent with this policy, please contact us before proceeding:

[email protected]

We also welcome constructive feedback about this policy and may update it periodically to ensure it remains clear, effective and consistent with recognised vulnerability-disclosure practices.

Schedule an appointment

We want you to know that we’re here to help. We have the resources, the knowledge and the experience to help you. 
Call us today to schedule your first appointment.