Skip to content

Vulnerability Disclosure Policy

Status: Phase 30 G4.T3 deliverable — public-facing coordinated disclosure discipline statement. Companion docs: docs/trust-center/index.md · docs/compliance/soc-2-tsc-2017-control-mapping.md (CC7.1 + CC7.4).


Reporting a Vulnerability

If you believe you have found a security vulnerability in Claimful, please report it via email to security@claimful.ai (PGP key fingerprint pending publication).

Please include:

  • Description of the vulnerability.
  • Steps to reproduce.
  • Affected URL or component.
  • Any proof-of-concept (encrypted attachment recommended).

Acknowledgment + Response

  • Acknowledgment: within 1 business day.
  • Triage update: within 5 business days.
  • Patch ETA: within 30 days for High/Critical; 90 days for Medium; best-effort for Low.

Safe Harbor

We will not pursue legal action or law-enforcement investigation against researchers who:

  • Make a good-faith effort to comply with this policy.
  • Avoid privacy violations, destruction of data, and interruption or degradation of services.
  • Use only their own accounts or accounts that they have explicit permission to test.
  • Do not exploit a security issue beyond what is necessary to confirm its existence.
  • Provide reasonable time for us to address the issue before public disclosure.

Out-of-Scope

The following are explicitly NOT eligible for safe harbor:

  • Denial-of-service attacks.
  • Social engineering of Claimful employees, contractors, or sub-processors.
  • Physical attacks on Claimful or sub-processor facilities.
  • Automated scanning that generates excessive traffic.

Coordinated Disclosure

We follow a 90-day coordinated disclosure timeline. After we patch the vulnerability + verify the fix, we may publish a disclosure on the status page (with researcher acknowledgment if desired) within 30 days.

Hall of Fame

Researchers who report valid vulnerabilities receive credit on this Trust Center page (with their consent). Hall of Fame entries are added under §"Acknowledgments" after the disclosure window closes.

Source ADRs

ADR 0017 (rate limiting) · ADR 0020 (Sentry PII / PHI scrubbing) · ADR 0031 (widget security).


Acknowledgments

None yet — first acknowledgment lands after the first valid external disclosure.

Cookie choices

Analytics and marketing scripts stay off until you choose them. Strictly necessary cookies keep security, forms, and consent settings working.

Cookie Policy