1. Overview
Claivi Technologies Inc. ("Claivi") takes the security of our platform and our customers' data seriously. We are committed to working with the security research community to identify and address vulnerabilities in a responsible manner.
This Vulnerability Disclosure Policy (VDP) outlines the rules and expectations for reporting security issues to Claivi. We encourage researchers, customers, and the general public to report potential vulnerabilities they discover in good faith.
Our security program is aligned with industry standards including ISO 27001, SOC 2, and OWASP guidelines for secure development.
2. Scope
This policy applies to all systems, applications, and services operated by Claivi under the claivi.com domain and its subdomains, including:
- In scope: The Claivi web application (app.claivi.com), public website (claivi.com), API endpoints (api.claivi.com), authentication flows, payment integration, and all subdomains explicitly owned and operated by Claivi.
Out of scope:
- Physical security attacks against Claivi facilities or personnel.
- Social engineering attacks against Claivi employees, contractors, or customers.
- Denial-of-service (DoS/DDoS) attacks of any kind.
- Attacks against third-party services that Claivi uses (Stripe, OpenAI, Cloudflare, AWS, etc.). Please report these to the respective provider.
- Vulnerabilities in third-party software that are already publicly disclosed with an available patch.
- Self-XSS, content injection on your own account that cannot be used to impact other users.
- Theoretical attacks without a reproducible proof of concept.
- Automated scanning that generates excessive traffic (rate limits may block you — manual testing preferred).
If you are unsure whether a vulnerability is in scope, please report it anyway. We will evaluate it and redirect you if needed.
3. How to report
Please report all security vulnerabilities to our dedicated security team:
Security contact
PGP encryption is available on request. We encourage encrypted reports for sensitive vulnerability disclosures.
We aim to acknowledge receipt of your report within 48 hours (excluding weekends and public holidays).
4. What to include
To help us respond quickly and effectively, please include the following in your report:
- Clear description: A concise summary of the vulnerability and the potential impact.
- Steps to reproduce: Detailed, step-by-step instructions to reproduce the issue. Include any specific configuration, account type, or conditions required.
- Affected version: Information about the affected component, including version numbers, endpoints, or page URLs.
- Proof of concept (PoC): A working PoC or demonstration of the vulnerability. For complex issues, a screen recording or annotated screenshots are helpful.
- Your contact information: An email address where we can reach you for follow-up questions.
- Disclosure preferences: Any specific timeline requests or preferences for coordinated disclosure.
5. Safe harbor
Claivi will not pursue legal action against individuals who engage in security research in good faith and in compliance with this policy. We consider such research as:
- Authorized access: Activities conducted in accordance with this policy are considered authorized access under applicable laws, including the Computer Fraud and Abuse Act (CFAA) in the United States and equivalent legislation in Canada.
- No legal action: We will not file a complaint or refer for prosecution any good-faith security researcher who complies with this policy.
- No DMCA action: We will not file a DMCA takedown notice against security research that complies with this policy.
- Recognition: With your permission, we will publicly acknowledge your contribution in our security hall of fame (if we maintain one) or in related security advisories.
Safe harbor conditions: You must (a) make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of our service; (b) not access or modify data beyond what is necessary to demonstrate the vulnerability; (c) not exploit the vulnerability beyond the minimum necessary to prove its existence; (d) promptly delete any data obtained during research once the vulnerability is confirmed; and (e) not publicly disclose the vulnerability without our prior written consent.
6. Our commitment to you
When you submit a report in accordance with this policy, we commit to:
Acknowledgment
We will acknowledge receipt of your report within 48 hours (excluding weekends).
Validation
We will validate the report and determine severity and impact within 5 business days.
Status updates
We will provide status updates every 5 business days until the issue is resolved.
Transparency
We will be transparent about remediation timeline and any limitations we encounter.
7. Disclosure preference
We prefer coordinated disclosure. Our standard approach is:
- Private disclosure: Please do not share vulnerability details publicly before we have had a reasonable opportunity to investigate and address the issue.
- Coordinated publication: We will work with you to agree on a timeline for public disclosure after a fix has been deployed. Typically, we aim for disclosure within 90 days of the fix being released.
- Recognition: With your consent, we will credit you in the security advisory published after the fix. If you prefer to remain anonymous, we respect that choice.
If we are unable to agree on a disclosure timeline, we will not unreasonably delay publication beyond 90 days from the date of the fix. If you believe we are not acting in good faith, please escalate to security@claivi.com.
8. Bug bounty
Claivi does not currently operate a paid bug bounty program. We deeply appreciate the time and effort that security researchers invest in finding and reporting vulnerabilities.
While we do not offer monetary rewards at this time, we are committed to:
- Publicly acknowledging your contribution (with your permission).
- Providing a detailed explanation of the vulnerability and its fix.
- Offering a free one-year subscription to the Claivi Enterprise plan for qualifying critical or high-severity findings, at our discretion.
- Fast-tracking your report and keeping you informed throughout the process.
We are evaluating the introduction of a formal paid bug bounty program. If you would like to be notified when it launches, contact security@claivi.com.
9. Contact
Claivi Security Team
Security reports: security@claivi.com
PGP key: Available on request
For non-security inquiries (privacy, legal, support), please see our other legal pages for the appropriate contact.