Clipform
Security

Vulnerability Disclosure Policy

How to report a security issue in Clipform.

We take the security of Clipform seriously and appreciate the work of security researchers who report issues responsibly.

How to report

Email security@clipform.io with a description of the issue, the steps to reproduce it, and any proof-of-concept material. We monitor this inbox directly.

Safe harbor

If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, we will not pursue legal action against you for that research. This means:

  • Only interact with accounts and data you own or have explicit permission to test
  • Give us a reasonable amount of time to investigate and fix an issue before disclosing it publicly
  • Do not access, modify, or delete data that does not belong to you beyond what is needed to demonstrate the issue

In scope

Production Clipform surfaces, including:

  • clipform.io and www.clipform.io (viewer and marketing)
  • api.clipform.io
  • app.clipform.io (dashboard), where applicable
  • The MCP server and OAuth endpoints under mcp.clipform.io

Out of scope

  • Denial of service or load-testing attacks
  • Social engineering of Clipform staff, customers, or support channels
  • Physical attacks against Clipform offices or infrastructure
  • Automated scanning noise without a demonstrated, exploitable finding (for example, a bare vulnerability scanner report with no proof of impact)

Bug bounty

We do not currently run a paid bug bounty program. We're grateful for responsible reports regardless, and will credit researchers who ask to be credited once a fix ships.

What to expect

We aim to acknowledge new reports within a few business days. From there we'll keep you updated as we investigate and work on a fix.

On this page