Security | Vulnerability Disclosure
We take security seriously. So do you.

Security researchers play an important role in keeping Clozd and our customers safe. If you've found a potential vulnerability in our platform, we want to hear from you — and we're committed to working with you transparently and respectfully throughout the process.This page describes how to report a vulnerability, what to expect from us, and the protections we extend to researchers who act in good faith.

Clozd does not operate a bug bounty program and does not offer financial compensation for vulnerability reports.

How to Report a Vulnerability

Submit your report through either of the channels below. To help us triage quickly, please include:

A clear description of the vulnerability and its potential impact

The affected URL, endpoint, or asset

Step-by-step instructions to reproduce the issue

Any tools or techniques used during discovery

Supporting evidence such as screenshots, logs, or proof-of-concept code

Submit a Report

HackerOne VDP: https://hackerone.com/clozd-vdp

Email: vdp@clozd.com

Milestone Trigger Standard Target
Initial acknowledgment Report received 5 business days 5 business days
Triage complete Acknowledgment sent 10 business days 10 business days
Critical resolution Triage complete 7 business days
High resolution Triage complete 30 business days
Medium resolution Triage complete 60 business days
Low resolution Triage complete 90 business days
What to Expect From Us

We respect the time researchers put into responsible disclosure. Here are our commitments once you submit a report:

Milestone Trigger Standard Target
Initial acknowledgment Report received 5 business days 5 business days
Triage complete Acknowledgment sent 10 business days 10 business days
Critical resolution Triage complete 7 business days
High resolution Triage complete 30 business days
Medium resolution Triage complete 60 business days
Low resolution Triage complete 90 business days

We will keep you informed as we investigate and work toward a fix. We ask that you give us a reasonable window to resolve the issue before any public or third-party disclosure.

Rules of Engagement

To keep research safe and legal for everyone, please follow these guidelines:

Do not access, modify, or delete data that does not belong to you. If you encounter customer data or PII at any point, stop immediately, purge it from your systems, and let us know.

Do not disrupt or degrade Clozd services, including denial-of-service and resource exhaustion attacks.

Do not use social engineering, phishing, or physical access techniques.

Do not exploit a vulnerability beyond what is necessary to confirm it exists.

Comply with all applicable laws and regulations in your jurisdiction and ours.

Program Scope

In Scope

We welcome reports on the following Clozd-owned assets:

Clozd Web Application and Platform (app.clozd.com)

Clozd-owned APIs

Out of Scope

The following are outside the scope of this program and will not be considered:

Physical security testing

Social engineering and phishing attacks

Denial of service and resource exhaustion attacks

Third-party services or infrastructure not owned or operated by Clozd

Safe Harbor

Clozd considers security research conducted in accordance with these guidelines to be authorized activity. We will not pursue civil or criminal legal action against researchers who:

Follow the rules of engagement set out on this page.

Act in good faith and avoid causing harm to Clozd, our customers, or our infrastructure.

Report findings promptly through the designated channels.

Do not exploit a vulnerability beyond confirming its existence.

Clozd reserves all legal rights in the event of noncompliance with these guidelines.