Vulnerability Disclosure Policy
How to report a security issue in Clipform.
We take the security of Clipform seriously and appreciate the work of security researchers who report issues responsibly.
How to report
Email security@clipform.io with a description of the issue, the steps to reproduce it, and any proof-of-concept material. We monitor this inbox directly.
Safe harbor
If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, we will not pursue legal action against you for that research. This means:
- Only interact with accounts and data you own or have explicit permission to test
- Give us a reasonable amount of time to investigate and fix an issue before disclosing it publicly
- Do not access, modify, or delete data that does not belong to you beyond what is needed to demonstrate the issue
In scope
Production Clipform surfaces, including:
clipform.ioandwww.clipform.io(viewer and marketing)api.clipform.ioapp.clipform.io(dashboard), where applicable- The MCP server and OAuth endpoints under
mcp.clipform.io
Out of scope
- Denial of service or load-testing attacks
- Social engineering of Clipform staff, customers, or support channels
- Physical attacks against Clipform offices or infrastructure
- Automated scanning noise without a demonstrated, exploitable finding (for example, a bare vulnerability scanner report with no proof of impact)
Bug bounty
We do not currently run a paid bug bounty program. We're grateful for responsible reports regardless, and will credit researchers who ask to be credited once a fix ships.
What to expect
We aim to acknowledge new reports within a few business days. From there we'll keep you updated as we investigate and work on a fix.