generated: '2026-08-05' method: searched probe: true source: https://withclutch.com/security/ summary: 'Clutch publishes a security page that names a security contact and explicitly invites reports of potential security issues. There is no formal responsible-disclosure or vulnerability-disclosure policy document, no bug bounty program (no HackerOne, Bugcrowd or Intigriti listing was found), and no /.well-known/security.txt on any Clutch host.' policy: [] contact: - security@withclutch.com security_page: https://withclutch.com/security/ bug_bounty: null security_txt: present: false probed: - {url: 'https://withclutch.com/.well-known/security.txt', status: 404} - {url: 'https://withclutch.com/security.txt', status: 404} - {url: 'https://api.clutch.partners/.well-known/security.txt', status: 404} program: penetration_testing: independent third-party penetration testing at least annually vulnerability_scanning: true threat_monitoring: true encryption: data encrypted at rest and in transit via TLS/SSL access_control: [SSO, 2FA, least privilege] vendor_risk: annual risk assessments before authorizing new vendors hosting: Amazon Web Services, US-based data centers evidence: - source: https://withclutch.com/security/ http_status: 200 kind: security-page quote: 'If you have any questions, comments or concerns or if you wish to report a potential security issue, please contact security@withclutch.com' - source: https://trust.withclutch.com/ http_status: 200 kind: trust-center note: Secureframe-hosted trust center listing a SOC 2 Type 2 report and a pentest executive report