Responsible disclosure

Found a security issue? Tell us directly.

Send suspected Clearplane vulnerabilities to the private security contact so we can review the report and coordinate with you.

Useful evidence

Help us reproduce what you found.

A concise report with a reliable reproduction path is easier to assess. Include only information needed to understand the issue.

  1. 01
    Affected version

    Include the Clearplane version, deployment shape, and affected component.

  2. 02
    Reproduction steps

    Describe the smallest sequence that demonstrates the issue and the expected result.

  3. 03
    Security impact

    Explain what an attacker could access, change, bypass, or disrupt.

  4. 04
    Supporting evidence

    Attach relevant requests, responses, logs, or a minimal proof of concept after removing secrets.

Protect people and systems

Keep the report safe and private.

01 / Permission

Test only authorized systems.

Assess deployments you own or have explicit permission to test.

02 / Data

Remove live secrets.

Do not send passwords, private keys, access tokens, or personal data.

03 / Disclosure

Report before publishing.

Please avoid public disclosure while the issue is being reviewed and coordinated.

03 / Report

Send the details privately.

We will use the same email thread to review the report and coordinate any follow-up.

Email security@clearplane.net