The Claromentis team work hard to secure and protect the availability, integrity, and confidentiality of the company and our customers and we are constantly striving to improve! If you have found a vulnerability, we’d be grateful for your assistance in helping to make our sites and services more secure for our team and our customers. We investigate and assess all reports as a priority. We’ve put together this policy to help you submit any vulnerability to us and to explain the process.
While Claromentis maintains other sites/services we ask that all security researchers submit vulnerability reports only for what is currently listed below:
We invite anyone who has found a security issue to contact our team using the following email address:
To ensure the confidentiality of the email, we ask that you anonymise, mask, or redact any sensitive data, or alternatively please encrypt the data using our public PGP key.
We ask that all submissions to this email address include:
Whilst we encourage you to report any security concerns you may have, we ask that you follow these guidelines:
Under no circumstance should you:
We commit to investigating and will attempt to resolve any vulnerability as soon as we can. We aim to respond to all reports within 14 days.
We will not initiate claims against you, so long as all terms set out in this responsible disclosure policy has been adhered to.
We don’t offer a financial reward for submissions, however we would like to recognise anyone who takes the time to submit genuine, medium/high risk vulnerabilities. We’ll assess each submission on a case by case basis. If the vulnerability you submit is something we weren’t aware of and we class it to be of significant risk, we’ll ask if you would like for your name to be shown proudly in our hall of fame below!
We’d like to publicly recognise and thank the following people who have helped report security vulnerabilities to us.