Contact: mailto:security@clario.finance Expires: 2026-12-31T23:59:59.000Z Encryption: https://clario.finance/pgp-key.txt Preferred-Languages: en Canonical: https://clario.finance/.well-known/security.txt Policy: https://clario.finance/trust Acknowledgments: https://clario.finance/security-acknowledgments # Security Vulnerability Reporting ## Reporting a Vulnerability If you discover a security vulnerability in Clario, please report it responsibly: 1. Email: security@clario.finance 2. Subject: "Security Vulnerability Report" 3. Include: - Description of the vulnerability - Steps to reproduce - Potential impact - Suggested fix (if applicable) ## What to Expect - Acknowledgment: Within 24 hours - Initial Assessment: Within 3 business days - Resolution Timeline: Depends on severity - Critical: 24-48 hours - High: 1 week - Medium: 2 weeks - Low: 1 month ## Responsible Disclosure Please: - Give us reasonable time to fix the issue before public disclosure - Don't access or modify user data without permission - Don't perform destructive testing We commit to: - Keep you updated on fix progress - Credit you in our security acknowledgments (if desired) - Not take legal action against good-faith security researchers ## Bug Bounty Program We're planning to launch a bug bounty program. Stay tuned for details! ## Out of Scope - Social engineering attacks - Physical security attacks - Denial of service attacks - Spam or social engineering content Thank you for helping us keep Clario secure!