Security

Powerful access. Deliberate controls.

Understand the practical controls around Vycko’s remote tools and how to report a potential security issue.

Last updated: 3 October 2026Newark Solutions Ltd trading as Vycko

Access controls that matter to the workflow.

The platform uses authenticated operator access and scoped API connections. MCP permissions distinguish read access from change access, with additional rights for console and estate-management operations. Customer scope, expiry and revocation constrain a connection’s authority.

Private OAuth connections are administrator-created. Remote tool requests follow the applicable platform and gateway checks, and actions are recorded in an audit trail. Reviewed runbooks use their configured execution and approval policy.

Controls depend on configuration and do not guarantee that every permitted action is safe. A connection with change rights can make immediate remote changes. Appropriate account security, customer permissions and engineer review remain essential.

Clear boundaries, rather than blanket promises.

The website does not claim a specific security certification, independent audit, penetration-test result or guaranteed protection against every threat. Security-readiness checks provide evidence and guidance; they are not certification.

Before a deployment, ask about hosting, data processing, backups, recovery, account controls, audit retention and the features enabled for your environment. Do not infer a service level or recovery commitment from a marketing example.

Report a potential vulnerability.

Email info@vycko.com with the subject Security report: Vycko. Include the affected page or component, a description, safe reproduction steps, the potential impact and a contact address. Remove tokens, passwords, personal data and customer content from attachments.

If you think a live credential has been exposed, revoke it through the relevant administrator and report the incident through your support arrangement. This public contact route is not a promise of round-the-clock incident response.

Keep research responsible.

A report is welcome; this page does not authorise testing. Do not access customer systems or data, disrupt services, alter or delete information, carry out social engineering or run broad automated scans without explicit written permission.

Use the minimum evidence needed to explain a concern and contact us before public disclosure so the issue can be assessed. This is not a bug-bounty programme, a payment offer or a legal safe-harbour commitment.

IT. On Autopilot.

See Vycko in your environment.

Tell us about the computers or clients you support.

Newark Solutions Ltd trading as Vycko