Public website
We protect public pages and form endpoints with secure transport, request validation, and controls against common abuse.
Security & Responsible Disclosure
If you believe you found a security issue on a public Clause5afe website or service, report it privately so we can understand the issue and respond responsibly.
Our approach
Our public guidance describes how to report a concern without publishing details that could create additional risk.
We protect public pages and form endpoints with secure transport, request validation, and controls against common abuse.
Restricted information and services are available only to authorized users through the access controls established for that service.
Initial reports should contain only the information needed to understand and investigate the issue safely.
Services operated by other organizations remain subject to their own authorization rules and disclosure programs.
Responsible disclosure
Good-faith security research should minimize harm, avoid unnecessary access to information, and give the affected organization enough information to investigate responsibly.
What to include
The hostname, route, feature, application, or integration where the issue was observed.
What you observed, why it may create security impact, and the conditions necessary for the issue to occur.
The minimum safe sequence needed to reproduce the behavior, avoiding unnecessary sensitive data or destructive actions.
A way to reach you for clarification if you are comfortable providing it. Anonymous security reports may be harder to investigate.
Program boundary
Publication of this page does not grant permission to access non-public systems, bypass authentication, test third-party infrastructure, violate another party's terms or rights, or expect compensation for unsolicited testing.
Report securely
Use the Security inquiry route. If online submission is unavailable, use the published phone or email option for an initial report.