Security
Report security flaws privately. We work with researchers to validate reports, fix vulnerabilities and coordinate disclosure.
US$1,000 security bounty
We pay US$1,000 for each verified, unique in-scope security flaw. The bounty goes to the first valid report of the underlying issue; duplicate reports do not receive additional rewards.
Reports must include a reproducible proof of security impact and follow the research guidelines below. We confirm eligibility and arrange payment after validation.
In scope
ClayMetrics-operated functionality on these exact hosts:
- claymetrics.com
- app.claymetrics.com
- api.claymetrics.com
- claymetrics.support
Hardware, unlisted hosts and third-party services are out of scope. Contact us before testing if you are unsure whether a target is covered.
Research guidelines
- Use accounts you own or have explicit permission to test. Keep testing to the minimum needed to demonstrate the flaw.
- If you encounter someone else's data, stop testing and report it immediately. Do not copy, download, retain, alter or share that data.
- Do not disrupt services, destroy data, conduct denial of service testing, use social engineering or attempt physical attacks.
- Report promptly and coordinate public disclosure with us, giving us a reasonable opportunity to fix the issue.
Scanner output, theoretical issues and configuration suggestions without demonstrated security impact do not qualify for a bounty. Neither do self-XSS or clickjacking on pages without sensitive actions.
Send a report
Include the affected URL, reproduction steps, security impact and supporting evidence. Use test data in screenshots and logs.
If you need an encrypted channel, contact us before sending sensitive details.
Report a security flawEmail security [at] claymetrics [dot] support.
What to expect
We acknowledge reports within 3 business days and aim to validate them within 10 business days. We keep you informed while resolving the issue.
We agree on coordinated disclosure with you, typically around 90 days after triage. These are communication commitments, not guaranteed fix dates. Public credit is optional.
Safe harbor
Good-faith research under this policy is authorized. We will not initiate or support legal action for that research or accidental, good-faith violations of this policy, including under the Computer Fraud and Abuse Act (CFAA) or similar anti-hacking laws.
We waive anti-circumvention claims under the DMCA and restrictions in our Terms of Use or Acceptable Use Policy to the extent needed for this research. If a third party brings a claim over research that complied with this policy, we will make our authorization known.
This safe harbor applies only to claims under ClayMetrics' control and does not bind third parties. Contact us if you are unsure whether an activity is authorized.