generated: '2026-08-13' method: searched source: https://clearbit.com/trust#security provider: Clearbit (HubSpot Breeze Intelligence) providerId: clearbit has_program: true program_type: security-contact description: >- Clearbit publishes a named security contact and an escalation path on its trust page, but no formal coordinated vulnerability disclosure policy, no safe-harbour language, no bug bounty and no /.well-known/security.txt. The contact is a mailbox and a phone number on a human page — a researcher can reach someone, but there is no published scope, no response SLA and nothing a machine can discover. contacts: - type: email value: security@clearbit.com source: https://clearbit.com/trust#security - type: phone value: '+1 888-237-8136' source: https://clearbit.com/trust#security policy_url: null safe_harbor: false bug_bounty: present: false platforms_checked: - hackerone - bugcrowd - intigriti note: No public bug bounty or VDP listing found for Clearbit on any major platform. security_txt: present: false probed: https://clearbit.com/.well-known/security.txt status: 404 note: >- Probed on all eight Clearbit hosts on 2026-08-13; 404 everywhere. See well-known/clearbit-well-known.yml. published_security_practices: - practice: Third-party penetration testing cadence: annual quote: >- "We engage third-party security experts to perform penetration tests on an annual basis and vulnerability scanning is performed on a regular basis." - practice: Regular vulnerability scanning cadence: ongoing - practice: Software Development Lifecycle Policy cadence: ongoing - practice: Employee background screening and NDAs at hire cadence: ongoing - practice: Security awareness and training program cadence: ongoing evidence: - url: https://clearbit.com/trust http_status: 200 fetched: '2026-08-13' matched: - security@clearbit.com - penetration tests on an annual basis - vulnerability scanning maintainers: - FN: Kin Lane email: kin@apievangelist.com