Vulnerability Disclosure Policy
Status: Phase 30 G4.T3 deliverable — public-facing coordinated disclosure discipline statement.
Companion docs: docs/trust-center/index.md · docs/compliance/soc-2-tsc-2017-control-mapping.md (CC7.1 + CC7.4).
Reporting a Vulnerability
If you believe you have found a security vulnerability in Claimful, please report it via email to security@claimful.ai (PGP key fingerprint pending publication).
Please include:
- Description of the vulnerability.
- Steps to reproduce.
- Affected URL or component.
- Any proof-of-concept (encrypted attachment recommended).
Acknowledgment + Response
- Acknowledgment: within 1 business day.
- Triage update: within 5 business days.
- Patch ETA: within 30 days for High/Critical; 90 days for Medium; best-effort for Low.
Safe Harbor
We will not pursue legal action or law-enforcement investigation against researchers who:
- Make a good-faith effort to comply with this policy.
- Avoid privacy violations, destruction of data, and interruption or degradation of services.
- Use only their own accounts or accounts that they have explicit permission to test.
- Do not exploit a security issue beyond what is necessary to confirm its existence.
- Provide reasonable time for us to address the issue before public disclosure.
Out-of-Scope
The following are explicitly NOT eligible for safe harbor:
- Denial-of-service attacks.
- Social engineering of Claimful employees, contractors, or sub-processors.
- Physical attacks on Claimful or sub-processor facilities.
- Automated scanning that generates excessive traffic.
Coordinated Disclosure
We follow a 90-day coordinated disclosure timeline. After we patch the vulnerability + verify the fix, we may publish a disclosure on the status page (with researcher acknowledgment if desired) within 30 days.
Hall of Fame
Researchers who report valid vulnerabilities receive credit on this Trust Center page (with their consent). Hall of Fame entries are added under §"Acknowledgments" after the disclosure window closes.
Source ADRs
ADR 0017 (rate limiting) · ADR 0020 (Sentry PII / PHI scrubbing) · ADR 0031 (widget security).
Acknowledgments
None yet — first acknowledgment lands after the first valid external disclosure.