We take security seriously. If you find a vulnerability, we want to hear from you — no bug bounty programme yet, but we acknowledge every valid report and fix issues promptly.
Email security@claudit.consulting with a description of the issue. Please include:
You can also use /.well-known/security.txt to find our contact details programmatically.
Acknowledgement
Within 2 business daysWe confirm receipt of your report and assign a tracking ID.
Triage
Within 5 business daysWe assess severity, reproduce the issue, and determine impact scope.
Fix & verification
Depends on severityCritical issues target a patch within 7 days. High within 30 days. We'll keep you updated.
Disclosure
Coordinated with youWe coordinate public disclosure timing with you. We don't disclose without your knowledge.
In scope
Out of scope
Researchers who follow these guidelines will not face legal action from us for their security research.
We don't currently run a formal paid bug bounty programme. We do publicly acknowledge researchers (with permission) in our Trust & Security page and aim to add a formal programme once we reach sufficient scale. A formal programme is planned — check back.
Security contact
security@claudit.consulting — PGP key available on request.