generated: '2026-09-05' method: searched source: >- https://clarivate.com/trust-center/ (HTTP 200) and the Trust Center disclosure section (the /information-security/responsible-vulnerability-disclosure-program/ URL now 301s there), with the HackerOne program confirmed live at https://hackerone.com/clarivate (HTTP 200) on 2026-09-05. description: >- Clarivate runs a named responsible-disclosure program on HackerOne with a published intake address. What it does NOT do is make any of it machine-discoverable: there is no /.well-known/security.txt on clarivate.com, www.clarivate.com, developer.clarivate.com or any of the three API hosts (see well-known/clarivate-well-known.yml), so an automated scanner finds nothing. program: exists: true type: responsible-disclosure platform: HackerOne platform_url: https://hackerone.com/clarivate platform_status: 200 policy_url: https://clarivate.com/trust-center/ policy_url_note: >- https://clarivate.com/information-security/responsible-vulnerability-disclosure-program/ now 301s to https://clarivate.com/trust-center/, where the disclosure statement and the hackerone@clarivate.com address are published. Probed 2026-09-05. trust_center: https://clarivate.com/trust-center/ contact_email: hackerone@clarivate.com bounty: unknown safe_harbor: unstated statement: >- "We encourage responsible reporting of potential security vulnerabilities in our sites and applications. We value the role of external security researchers and work collaboratively to verify and address reported issues. If you identify a concern report it through our HackerOne Responsible Disclosure Program or email a clear description of the issue, its location and steps to reproduce it, to hackerone@clarivate.com." submission_requirements: - A clear description of the issue - Its location - Steps to reproduce it security_txt: served: false probed: - url: https://clarivate.com/.well-known/security.txt status: 404 - url: https://www.clarivate.com/.well-known/security.txt status: 404 - url: https://developer.clarivate.com/.well-known/security.txt status: 404 - url: https://api.clarivate.com/.well-known/security.txt status: 200 note: SPA shell, not a document related: product_security: https://clarivate.com/information-security/product-security/ security_standards: https://clarivate.com/information-security/summary-of-standards/ information_security_hub: https://clarivate.com/information-security/ gap: finding: >- A one-line RFC 9116 /.well-known/security.txt on clarivate.com pointing Policy: at the responsible-disclosure page and Contact: at hackerone@clarivate.com would make an existing, funded program machine-discoverable. Today the program is invisible to every automated check. maintainers: - FN: Kin Lane email: kin@apievangelist.com