generated: '2026-08-13' method: searched source: https://www.clari.com/vulnerability-disclosure-policy/ name: Clari Vulnerability Disclosure Policy description: >- Clari runs a self-hosted vulnerability disclosure program with a discretionary severity-based reward. It is linked from https://www.clari.com/security/ and is NOT discoverable through /.well-known/security.txt — Clari serves no security.txt on any host (404 on the API hosts, HTTP 200 marketing HTML soft-404 on www.clari.com). url: https://www.clari.com/vulnerability-disclosure-policy/ http_status: 200 program_type: self-hosted platform: none bug_bounty: true bounty_note: >- "Our rewards are based on the severity of a vulnerability." All program parameters and payments are "up to the discretion of Clari and may change at any time." Minors and sanctioned individuals are ineligible. reporting: channel: web form location: form at the bottom of https://www.clari.com/vulnerability-disclosure-policy/ email: null pgp_key: null verbatim: "Please submit any potential findings to our program via the form at the bottom of this page." safe_harbor: present: true scope: limited verbatim: >- "Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service." caveat: >- Researchers must comply with applicable law and Clari policy; unauthorized access and retention of data are prohibited. This is good-faith language rather than a full legal safe harbor. response_commitment: sla: none verbatim: >- Clari will "make every effort to quickly resolve the issue" and remain "responsive" with updates during triage and remediation. No timeline is guaranteed. in_scope_priorities: - compromise of user data - account takeover - remote code execution - unauthorized access - authentication bypass out_of_scope: - social engineering - phishing - denial of service - missing security best practices (SPF/DKIM/DMARC, CSP) - unpatched browser issues - open redirects without a chained impact related: - name: Report a Scam url: https://www.clari.com/security/report-a-scam/ note: A separate brand/fraud reporting channel, not a vulnerability channel. gaps: - No /.well-known/security.txt on any Clari host, so the policy is invisible to automated discovery (RFC 9116). - No reporting email or PGP key; the only channel is a web form. - No published triage or remediation timeline. x-evidence: fetched: '2026-08-13' probes: - url: https://www.clari.com/vulnerability-disclosure-policy/ http_status: 200 - url: https://www.clari.com/security/ http_status: 200 finding: 'Links the policy — "To review our guidelines and submit an issue, see our Vulnerability Disclosure Policy"' - url: https://www.clari.com/.well-known/security.txt http_status: 200 finding: Marketing HTML shell (soft-404). No security.txt document is served. - url: https://api.clari.com/.well-known/security.txt http_status: 404