As a security company, keeping our customers safe is our primary concern. Clear Infosec uses a Secure Development Lifecycle to build security into its products from design through development and release. Even so, vulnerabilities can escape detection or emerge after release. We investigate every vulnerability report we receive and take the best course of action to protect our services and customers.
Reporting a vulnerability
If you are a security researcher and have discovered a vulnerability in our website or products, we appreciate your help in disclosing it responsibly. Please share the details privately with our security team at info@clearinfosec.com.
We review each submission to determine whether the finding is valid and has not been previously reported. To help us reproduce and act on an issue efficiently, please include detailed steps to reproduce it.
Researcher guidelines
To remain compliant with this policy, security researchers must not:
- Access, download, or modify data that does not belong to them.
- Execute or attempt any Denial of Service (DoS) attack against a Clear Infosec website, product, or service.
- Post, transmit, upload, link to, send, or store any malicious software on a Clear Infosec website or service.
- Test in a way that sends unsolicited or unauthorized junk mail or spam to our employees and customers.
- Test in a way that degrades or negatively impacts the operation of any Clear Infosec service or system.
- Test third-party applications, websites, or services that integrate with or link to Clear Infosec.
Our commitment
When you report responsibly, we will:
- Acknowledge receipt of your report within 48 business hours of submission.
- Work with you to understand the issue and agree on timelines for a fix and disclosure.
- Correct the vulnerability within a reasonable time frame before public disclosure, so a tested fix is available to customers.
- Notify you when the vulnerability is resolved so it can be retested and confirmed as remediated.
- Publicly acknowledge your responsible disclosure, if you would like credit.
Out of scope
The following are generally considered out of scope:
- Attacks on email servers or protocols, and email security such as SPF, DMARC, and DKIM, or email spam.
- Simple IP or port scanning reports.
- Email security best practices or controls.
- Software or infrastructure bannering and fingerprinting.
- Domain-based phishing, typosquatting, punycode, bitflips, and similar techniques.
- Clickjacking or self-XSS.
- Publicly resolvable or accessible DNS records for internal hosts or infrastructure.
Questions about this policy?
Contact us and we will be glad to help.