Security & Vulnerability Disclosure Policy
Draft — pending legal review · Last updated July 16, 2026
1. Our commitment
ClayMetrics welcomes good-faith security research. We practice coordinated disclosure: if you find a vulnerability in one of our systems, tell us privately, give us a reasonable window to fix it, and we'll work the issue with you and credit you if you'd like. This policy explains what is in scope, how to report, the legal safe harbor we extend to good-faith researchers, and what you can expect from us. We do not operate a paid bug bounty — see section 7.
2. Scope
In scope
- claymetrics.com — our marketing website.
- app.claymetrics.com — the ClayMetrics web application.
- api.claymetrics.com — the ClayMetrics API.
- claymetrics.support — our support-desk email and web intake.
Out of scope
Third-party infrastructure. We build on Cloudflare, Clerk, Resend, Fly.io, and BetterStack. Vulnerabilities in those platforms are out of scope here and should be reported to each vendor's own disclosure program — our safe harbor cannot authorize testing that would violate their terms.
Hardware. The Trapper trap controller and the ClubNode appliance are out of scope for this policy at this time. This policy covers our web, API, and support-desk surface only; a hardware disclosure scope may be added in a future revision.
3. Legal safe harbor
When you make a good-faith effort to comply with this policy during your research, we will consider your research to be authorized, and:
- Anti-hacking laws. We will not initiate or support legal action against you for accidental, good-faith violations of this policy, including under the U.S. Computer Fraud and Abuse Act (CFAA) or similar state laws.
- DMCA. We waive any claim against you under the anti-circumvention provisions of the Digital Millennium Copyright Act (DMCA) for good-faith research conducted under this policy.
- Terms of service. We waive any relevant restriction in our Terms of Use and Acceptable Use Policy to the extent necessary to permit the good-faith security testing described here.
- Good faith. We will not pursue or support legal action for good-faith, accidental violations of this policy. If a third party brings legal action against you for activity that complied with this policy, we will make our authorization known.
This safe harbor applies only to legal claims under ClayMetrics' control. It does not bind third parties (including the out-of-scope infrastructure providers above), and you remain responsible for complying with their terms. If in doubt about whether an action is authorized, ask us first at [email protected] before proceeding.
4. How to report
Email [email protected]. To help us triage quickly, please include:
- The affected asset or URL.
- The vulnerability type.
- Step-by-step reproduction or a proof-of-concept.
- The impact — what an attacker could do.
- Any supporting screenshots or logs. You can reply to our confirmation email to attach files.
Prefer to encrypt? Say so in your first message and we'll share a PGP key or set up a secure channel. Please avoid sending detailed exploit information in plain text if you'd rather encrypt first.
5. What to expect
These are communication commitments — how quickly we'll respond and keep you informed — not guaranteed remediation dates:
- We acknowledge your report within 3 business days.
- We aim to triage and validate within 10 business days.
- We keep you updated at a steady cadence while we work the issue.
- We coordinate public disclosure with you — typically around 90 days after triage, by mutual agreement. Remediation timing depends on severity and complexity.
6. Out-of-scope findings
The following generally do not qualify unless you can demonstrate a concrete security impact:
- Denial of service (DoS/DDoS) and volumetric or resource-exhaustion testing.
- Social engineering of our staff, users, or contractors; physical attacks.
- Missing security headers or cookie flags with no demonstrated impact.
- SPF, DKIM, or DMARC configuration suggestions.
- Automated scanner output or theoretical vulnerabilities without a working proof-of-concept.
- Self-XSS.
- Clickjacking on pages with no sensitive actions.
- Rate-limiting reports without a demonstrated impact.
7. No bounty, but credit
ClayMetrics does not operate a paid bug bounty and does not offer monetary rewards for reports at this time. We deeply value the work researchers do, and — with your permission — we're glad to credit you publicly in a security acknowledgments page once your report is resolved. Let us know the name or handle you'd like to be credited under, or ask to remain anonymous.
8. Contact
ClayMetrics Security
[email protected]