generated: '2026-09-06' method: searched source: https://www.aclaimant.com/responsible-disclosure program: type: responsible-disclosure published: true url: https://www.aclaimant.com/responsible-disclosure bug_bounty: false bounty_platform: null safe_harbor_stated: false contact: email: security@aclaimant.com pgp: true pgp_note: >- The policy asks reporters to encrypt findings with Aclaimant's PGP key; the key is linked from the responsible-disclosure page rather than served at a /.well-known path. security_txt: served: false probed: - url: https://www.aclaimant.com/.well-known/security.txt status: 404 - url: https://api.aclaimant.com/.well-known/security.txt status: 404 - url: https://developer.aclaimant.com/.well-known/security.txt status: 403 policy: reporting_steps: - Email findings to security@aclaimant.com as soon as possible - Encrypt findings using Aclaimant's PGP key - Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of service - Only interact with accounts you own or with explicit permission of the account holder - Allow Aclaimant reasonable time to resolve the issue before public or third-party disclosure exclusions: - Denial of service - Spamming - Social engineering (including phishing) of Aclaimant staff or contractors - Physical attempts against Aclaimant property or data centers - Knowingly posting, transmitting, uploading, linking to, sending or storing malicious software - Testing that would result in unsolicited or unauthorized junk mail, spam or pyramid schemes evidence: - url: https://www.aclaimant.com/responsible-disclosure status: 200