Security & Responsible Disclosure

Help us protect Clause5afe and the people who rely on it.

If you believe you found a security issue on a public Clause5afe website or service, report it privately so we can understand the issue and respond responsibly.

Our approach

Protect access and limit unnecessary exposure.

Our public guidance describes how to report a concern without publishing details that could create additional risk.

Public website

We protect public pages and form endpoints with secure transport, request validation, and controls against common abuse.

Access control

Restricted information and services are available only to authorized users through the access controls established for that service.

Data care

Initial reports should contain only the information needed to understand and investigate the issue safely.

Third-party services

Services operated by other organizations remain subject to their own authorization rules and disclosure programs.

Responsible disclosure

Help us understand the issue without creating a second incident.

Good-faith security research should minimize harm, avoid unnecessary access to information, and give the affected organization enough information to investigate responsibly.

  • Do not access, copy, modify, delete, retain, or disclose data that is not your own.
  • Do not perform destructive testing, denial-of-service activity, resource exhaustion, or actions that could impair service for other users.
  • Do not use social engineering, phishing, physical intrusion, credential theft, extortion, or threats as part of vulnerability research.
  • Do not test any non-public Clause5afe, client, employee, or third-party system without explicit written authorization for that specific environment.
  • Provide enough detail to reproduce and understand the issue without publicly disclosing exploit instructions before Clause5afe has had a reasonable opportunity to assess it.
  • If you encounter sensitive information unexpectedly, stop testing, preserve only the minimum information needed to report the issue, and notify Clause5afe through the designated route.

What to include

A useful report is specific and minimal.

Affected surface

The hostname, route, feature, application, or integration where the issue was observed.

Issue description

What you observed, why it may create security impact, and the conditions necessary for the issue to occur.

Reproduction information

The minimum safe sequence needed to reproduce the behavior, avoiding unnecessary sensitive data or destructive actions.

Contact information

A way to reach you for clarification if you are comfortable providing it. Anonymous security reports may be harder to investigate.

Program boundary

Responsible disclosure is not an open bug-bounty authorization.

Publication of this page does not grant permission to access non-public systems, bypass authentication, test third-party infrastructure, violate another party's terms or rights, or expect compensation for unsolicited testing.

Report securely

Found something that may affect Clause5afe security?

Use the Security inquiry route. If online submission is unavailable, use the published phone or email option for an initial report.

Report Security Issue