Test only authorized systems.
Assess deployments you own or have explicit permission to test.
Responsible disclosure
Send suspected Clearplane vulnerabilities to the private security contact so we can review the report and coordinate with you.
Your report
Useful evidence
A concise report with a reliable reproduction path is easier to assess. Include only information needed to understand the issue.
Include the Clearplane version, deployment shape, and affected component.
Describe the smallest sequence that demonstrates the issue and the expected result.
Explain what an attacker could access, change, bypass, or disrupt.
Attach relevant requests, responses, logs, or a minimal proof of concept after removing secrets.
Before sending
Protect people and systems
Assess deployments you own or have explicit permission to test.
Do not send passwords, private keys, access tokens, or personal data.
Please avoid public disclosure while the issue is being reviewed and coordinated.
We will use the same email thread to review the report and coordinate any follow-up.