Clarity Security

Report security issues responsibly.

If you have found a possible vulnerability in Clarity or this website, give us enough information to reproduce it safely — without accessing anyone else’s data.

A researcher documents a minimal technical reproduction
Four separate, anonymised parts of a security report

As little as possible. As much as necessary.

A good report protects people while it is being written.

Reproduction steps, impact, environment and minimal evidence belong together, but real credentials, other people’s content and active secrets do not. This lets a possible vulnerability be investigated without needlessly increasing the risk.

From report to decision

Five steps. The smallest possible attack surface.

This process describes how a responsible report is intended to be handled. It does not promise a fixed deadline and is not a published bug bounty programme.

01

Limit the intake

We separate contact details, the affected surface and a minimal reproduction from attachments or content that the investigation does not need.

02

Isolate the reproduction

A possible vulnerability is reproduced with our own test data and the least possible access — never inside another person’s account or data.

03

Assess the impact

Affected identity, confidentiality, integrity, availability and possible safeguard boundaries are assessed separately.

04

Verify the change

A fix needs regression tests at the affected boundary. A message disappearing from the interface is not security evidence by itself.

05

Document the outcome

The result, remaining boundary and required follow-up are recorded clearly. Public acknowledgement only happens with consent.

Scope

What this page covers — and what it does not.

Responsible disclosure starts with a clear boundary. Without one, even a well-intentioned test can become a risk.

Web
This Clarity website, its account, support and session surfaces, and Clarity endpoints it explicitly calls.
App
The current Clarity app and services operated by Audecius. Third-party services must still be reported through their own programmes.
No testing permission
This contact page does not authorise scans, load tests, bypassing access controls or access to anyone else’s data.
No bug bounty promise
No rewards, safe-harbour terms or fixed response times are currently published. Those commitments require a reviewed programme first.
Urgent account security
If you suspect an account has been compromised, stop testing. Use Support with the subject Account security instead.

What your report should include

  • Affected surface, URL, app version and device
  • Steps to reproduce and the expected behaviour
  • Possible impact and any protective measures already taken
  • Only the minimum necessary anonymised evidence

Please do not

  • Use social engineering, phishing or attacks against employees
  • Cause disruption, run load tests or send automated requests at scale without approval
  • Access, change or publish anyone else’s data
  • Make demands under threat of publication

What should be visible afterwards

A report should have a traceable receipt, a tightly bounded reproduction and an assessment of the affected data and functions. We currently promise neither a fixed response time nor a reward; both would require a reviewed process and a published programme.

Contact

Until a dedicated security contact is published and secured, use support@audeciusofficial.com with the subject “Security Report”. Do not send active secrets or personal data without encryption.

Machine-readable contact: security.txt

Clarity Security — Report vulnerabilities responsibly